We can fetch public certificate from server with IP or domain. ex: 10.10.1.20
openssl s_client -connect 10.10.1.20:443 < /dev/null | sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' > certificate.crt
Make sure that certificate.crt
only contain between the BEGIN CERTIFICATE and END CERTIFICATE lines
-----BEGIN CERTIFICATE-----
..........................
-----END CERTIFICATE-----