How to Download a Website’s SSL Certificate
Learn how to view and save a website’s public TLS certificate with Firefox, OpenSSL, Python, and Node.js—and verify the result safely.
If you need to download a website’s SSL certificate, retrieve the public TLS certificate that the HTTPS server presents. You can inspect it in Firefox or use OpenSSL to display and save the PEM certificate. The certificate contains public identity and key information; it does not contain the server’s private key.
For repeatable work, use the command-line method:
openssl s_client -connect example.com:443 -servername example.com -showcerts
Replace example.com with the hostname you need. The -servername option supplies SNI so a server hosting multiple HTTPS sites can return the certificate for the intended hostname. OpenSSL documents -connect, -servername, and -showcerts in its s_client manual.
What you are downloading
“SSL certificate” is the common phrase, but modern websites use TLS. A TLS server certificate helps prove the website’s identity and protects the connection. Firefox Help describes TLS server certificates as verifying the ownership and integrity of information from websites you visit.
The downloaded file is public. It is different from:
- The private key: kept by the site operator and never exposed by a normal HTTPS connection.
- A client certificate: used by a user or device to authenticate to a server.
- A certificate-authority certificate: a trust anchor installed in an operating system, browser, or application.
Method 1: View a certificate in Firefox
Firefox documents this route for inspecting a site certificate. Interface labels can change between browser versions, so use it as the Firefox flow rather than a universal browser procedure.
- Open the HTTPS website in Firefox.
- Click the site-information icon beside the address bar.
- Open the secure-connection details.
- Choose More information.
- In the Page Info window, choose View Certificate.
The certificate view can show the server certificate and the certificates in the presented chain, including intermediates and, where available, a root certificate. Firefox also exposes fields such as the subject, issuer, validity dates, fingerprints, and subject alternative names (SANs). See Mozilla’s Secure website certificate documentation for the documented steps and certificate details.
Firefox’s certificate viewer is useful when you want visual inspection. Do not assume every browser version provides the same export button or file format. If you need a file for a script, container, proxy, or trust store, use OpenSSL or export from the browser version you are running after confirming its format.
Method 2: Download with OpenSSL
Display the certificates sent by the server
openssl s_client \
-connect example.com:443 \
-servername example.com \
-showcerts
The output includes diagnostic text and one or more PEM blocks. A PEM certificate starts with -----BEGIN CERTIFICATE----- and ends with -----END CERTIFICATE-----. The first block is commonly the leaf certificate for the hostname, followed by intermediate certificates, but the exact chain depends on the server configuration.
Save a certificate block as a PEM file
Copy the certificate block you need, including both delimiter lines, into a file such as example-com.pem:
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
For a repeatable shell extraction, this command keeps the first PEM block from the OpenSSL output:
openssl s_client -connect example.com:443 -servername example.com -showcerts 2>/dev/null \
| awk '/-----BEGIN CERTIFICATE-----/{n++} n==1{print} /-----END CERTIFICATE-----/ && n==1{exit}' \
> example-com.pem
That saves the first certificate only. If you need an intermediate certificate, select the next PEM block instead. A server may not send every certificate that a client could use to build a trusted chain.
Inspect the saved certificate
openssl x509 -in example-com.pem -noout -subject -issuer -dates -fingerprint -ext subjectAltName
To print the complete decoded certificate:
openssl x509 -in example-com.pem -text -noout
Python: retrieve and inspect the peer certificate
Python’s standard library can open a TLS connection and retrieve the peer certificate in decoded form. This is useful for checks in automation; it does not replace trust validation unless you configure the SSL context appropriately.
import socket
import ssl
hostname = "example.com"
port = 443
context = ssl.create_default_context()
with socket.create_connection((hostname, port), timeout=10) as sock:
with context.wrap_socket(sock, server_hostname=hostname) as tls_sock:
certificate = tls_sock.getpeercert()
print("subject:", certificate.get("subject"))
print("issuer:", certificate.get("issuer"))
print("notBefore:", certificate.get("notBefore"))
print("notAfter:", certificate.get("notAfter"))
print("SANs:", certificate.get("subjectAltName"))
To save the peer certificate in DER form, use getpeercert(binary_form=True) and write the returned bytes. Convert DER to PEM when required by the receiving application:
import socket
import ssl
hostname = "example.com"
context = ssl.create_default_context()
with socket.create_connection((hostname, 443), timeout=10) as sock:
with context.wrap_socket(sock, server_hostname=hostname) as tls_sock:
der = tls_sock.getpeercert(binary_form=True)
with open("example-com.der", "wb") as output:
output.write(der)
Node.js: retrieve the peer certificate
Node.js can inspect the certificate negotiated by a TLS connection. The example below enables normal certificate validation and SNI, then prints the peer certificate fields.
import tls from 'node:tls';
const hostname = 'example.com';
const socket = tls.connect({
host: hostname,
port: 443,
servername: hostname,
rejectUnauthorized: true
}, () => {
const certificate = socket.getPeerCertificate(true);
console.log({
subject: certificate.subject,
issuer: certificate.issuer,
valid_from: certificate.valid_from,
valid_to: certificate.valid_to,
subjectaltname: certificate.subjectaltname
});
socket.end();
});
socket.setTimeout(10000, () => socket.destroy(new Error('TLS connection timed out')));
socket.on('error', (error) => console.error(error.message));
Set rejectUnauthorized to false only for controlled diagnostics where you explicitly need to inspect an otherwise untrusted endpoint. Do not use that setting to make production trust checks pass.
PEM versus DER
| Format | Appearance | Typical use |
|---|---|---|
| PEM | Text with BEGIN CERTIFICATE and END CERTIFICATE markers |
Configuration files, OpenSSL commands, many servers and libraries |
| DER | Binary encoding with no readable delimiters | Applications or systems that require a binary certificate |
Confirm the format required by the application receiving the certificate. Convert a PEM file to DER with:
openssl x509 -in example-com.pem -outform DER -out example-com.der
Convert DER back to PEM with:
openssl x509 -inform DER -in example-com.der -outform PEM -out example-com.pem
Validate the certificate before using it
- Check the hostname. Confirm that the intended DNS name appears in the certificate’s Subject Alternative Name extension. A certificate for another name is not the right certificate for your endpoint.
- Check the validity period. Inspect
notBeforeandnotAfteragainst the current date and your deployment’s clock. - Check the issuer and chain. Confirm that the issuer is expected and that the chain leads to a root trusted by the environment that will use the file.
- Use SNI. When a host shares an IP address with other sites, include
-servernamein OpenSSL orservernamein Node.js. - Check the file type. Search for certificate delimiters. Never publish, upload, or request a server private key as part of this process.
Downloading a certificate does not prove that it is valid or trusted. Trust depends on hostname verification, validity dates, signatures, and the trust store used by the client.
Common errors and fixes
| Error or symptom | Likely cause | Fix |
|---|---|---|
no peer certificate available |
The connection did not complete TLS negotiation, or the endpoint is not serving TLS on that port. | Confirm the hostname and port, then retry with -connect host:443. Check whether a proxy or firewall is intercepting the connection. |
| The certificate is for a different site | SNI was omitted, or the server selected its default virtual host. | Add -servername target.example and use the same hostname in Python or Node.js. |
| Only one certificate appears | The server sent only its leaf certificate. | Save the leaf certificate and obtain required intermediates from the site operator or the issuing CA. Do not assume the server sends every possible chain component. |
certificate verify failed |
The chain is untrusted, expired, incomplete, or the hostname does not match. | Inspect issuer, dates, SANs, and the client trust store. Fix the chain or hostname rather than disabling verification. |
| OpenSSL command is not found | OpenSSL is not installed or is absent from PATH. |
Install OpenSSL using your operating system’s package manager, then confirm with openssl version. |
| The saved file cannot be parsed | Diagnostic text, missing delimiters, or the wrong encoding was saved. | Keep only one complete PEM block, or tell OpenSSL -inform DER when the input is binary DER. |
| Firefox shows a warning | The site may have an expired certificate, hostname mismatch, untrusted issuer, or another TLS problem. | Read the warning details and inspect the certificate fields. Do not treat a warning page as proof that the certificate is safe. |
Browser or OpenSSL?
| Need | Best route |
|---|---|
| Quick visual inspection | Firefox certificate viewer |
| Repeatable checks in scripts or CI | OpenSSL, Python, or Node.js |
| Several certificates from a presented chain | OpenSSL with -showcerts |
| A file for another application | OpenSSL, after confirming PEM or DER requirements |
Performance, reliability, and cost considerations
- Performance: A TLS inspection requires DNS resolution, TCP connection setup, and TLS negotiation. Keep connection timeouts finite in automation and avoid opening a new connection for every check when your client can reuse connections.
- Reliability: Run checks from the same network conditions as the application that will consume the certificate. Proxies, firewalls, SNI, IPv4 versus IPv6, and clock skew can change the result.
- Chain handling: Store the leaf and intermediates separately when your target software expects a specific order. The presented chain is not guaranteed to include every trust anchor.
- Cost: Firefox and OpenSSL perform local inspection. Your costs come from the machine, network, and any monitoring infrastructure you choose to run.
Or skip the browser setup
If your goal is to capture a visual record of the HTTPS page after checking it, ScreenshotNeo provides a website screenshot API. The request is one GET call, and the API can return PNG, JPEG, WebP, or PDF output.
See the ScreenshotNeo API documentation for the available options. A basic call is:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://example.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://example.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
ScreenshotNeo removes cookie banners, newsletter popups, and chat widgets before the shot. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and response headers identify the page verdict and billing result. Its MCP server lets AI agents use take_screenshot, get_page_info, and capture_pdf. The Free plan includes 1,000 screenshots each month with no card, and paid plans start at $5 for 3,000 shots.
Create a free ScreenshotNeo account to get started.
FAQ
Can I download a website’s private key?
No. A normal HTTPS connection exposes the public certificate only. The private key must remain with the site operator.
Does the certificate prove the website is trustworthy?
It proves what the certificate and validating chain assert when hostname, dates, signatures, and trust-store checks succeed. It does not guarantee that the website’s content or business is safe.
Why does OpenSSL show multiple certificates?
-showcerts displays certificates sent by the server, commonly a leaf certificate and one or more intermediates. The server may omit some chain components.
Should I save PEM or DER?
Use the format required by the software receiving the file. PEM is text with certificate delimiters; DER is binary.
Why is SNI necessary?
Many HTTPS sites share an IP address. SNI tells the server which hostname you want so it can select the matching certificate.


