ScreenshotNeo

BlogHow-to

How to Download a Website’s SSL Certificate

Learn how to view and save a website’s public TLS certificate with Firefox, OpenSSL, Python, and Node.js—and verify the result safely.

By the ScreenshotNeo team1 October 20268 min read

If you need to download a website’s SSL certificate, retrieve the public TLS certificate that the HTTPS server presents. You can inspect it in Firefox or use OpenSSL to display and save the PEM certificate. The certificate contains public identity and key information; it does not contain the server’s private key.

For repeatable work, use the command-line method:

openssl s_client -connect example.com:443 -servername example.com -showcerts

Replace example.com with the hostname you need. The -servername option supplies SNI so a server hosting multiple HTTPS sites can return the certificate for the intended hostname. OpenSSL documents -connect, -servername, and -showcerts in its s_client manual.

What you are downloading

“SSL certificate” is the common phrase, but modern websites use TLS. A TLS server certificate helps prove the website’s identity and protects the connection. Firefox Help describes TLS server certificates as verifying the ownership and integrity of information from websites you visit.

The downloaded file is public. It is different from:

  • The private key: kept by the site operator and never exposed by a normal HTTPS connection.
  • A client certificate: used by a user or device to authenticate to a server.
  • A certificate-authority certificate: a trust anchor installed in an operating system, browser, or application.

Method 1: View a certificate in Firefox

Firefox documents this route for inspecting a site certificate. Interface labels can change between browser versions, so use it as the Firefox flow rather than a universal browser procedure.

  1. Open the HTTPS website in Firefox.
  2. Click the site-information icon beside the address bar.
  3. Open the secure-connection details.
  4. Choose More information.
  5. In the Page Info window, choose View Certificate.

The certificate view can show the server certificate and the certificates in the presented chain, including intermediates and, where available, a root certificate. Firefox also exposes fields such as the subject, issuer, validity dates, fingerprints, and subject alternative names (SANs). See Mozilla’s Secure website certificate documentation for the documented steps and certificate details.

Firefox’s certificate viewer is useful when you want visual inspection. Do not assume every browser version provides the same export button or file format. If you need a file for a script, container, proxy, or trust store, use OpenSSL or export from the browser version you are running after confirming its format.

Method 2: Download with OpenSSL

Display the certificates sent by the server

openssl s_client \
  -connect example.com:443 \
  -servername example.com \
  -showcerts

The output includes diagnostic text and one or more PEM blocks. A PEM certificate starts with -----BEGIN CERTIFICATE----- and ends with -----END CERTIFICATE-----. The first block is commonly the leaf certificate for the hostname, followed by intermediate certificates, but the exact chain depends on the server configuration.

Save a certificate block as a PEM file

Copy the certificate block you need, including both delimiter lines, into a file such as example-com.pem:

-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----

For a repeatable shell extraction, this command keeps the first PEM block from the OpenSSL output:

openssl s_client -connect example.com:443 -servername example.com -showcerts 2>/dev/null \
  | awk '/-----BEGIN CERTIFICATE-----/{n++} n==1{print} /-----END CERTIFICATE-----/ && n==1{exit}' \
  > example-com.pem

That saves the first certificate only. If you need an intermediate certificate, select the next PEM block instead. A server may not send every certificate that a client could use to build a trusted chain.

Inspect the saved certificate

openssl x509 -in example-com.pem -noout -subject -issuer -dates -fingerprint -ext subjectAltName

To print the complete decoded certificate:

openssl x509 -in example-com.pem -text -noout

Python: retrieve and inspect the peer certificate

Python’s standard library can open a TLS connection and retrieve the peer certificate in decoded form. This is useful for checks in automation; it does not replace trust validation unless you configure the SSL context appropriately.

import socket
import ssl

hostname = "example.com"
port = 443

context = ssl.create_default_context()
with socket.create_connection((hostname, port), timeout=10) as sock:
    with context.wrap_socket(sock, server_hostname=hostname) as tls_sock:
        certificate = tls_sock.getpeercert()
        print("subject:", certificate.get("subject"))
        print("issuer:", certificate.get("issuer"))
        print("notBefore:", certificate.get("notBefore"))
        print("notAfter:", certificate.get("notAfter"))
        print("SANs:", certificate.get("subjectAltName"))

To save the peer certificate in DER form, use getpeercert(binary_form=True) and write the returned bytes. Convert DER to PEM when required by the receiving application:

import socket
import ssl

hostname = "example.com"
context = ssl.create_default_context()

with socket.create_connection((hostname, 443), timeout=10) as sock:
    with context.wrap_socket(sock, server_hostname=hostname) as tls_sock:
        der = tls_sock.getpeercert(binary_form=True)

with open("example-com.der", "wb") as output:
    output.write(der)

Node.js: retrieve the peer certificate

Node.js can inspect the certificate negotiated by a TLS connection. The example below enables normal certificate validation and SNI, then prints the peer certificate fields.

import tls from 'node:tls';

const hostname = 'example.com';

const socket = tls.connect({
  host: hostname,
  port: 443,
  servername: hostname,
  rejectUnauthorized: true
}, () => {
  const certificate = socket.getPeerCertificate(true);
  console.log({
    subject: certificate.subject,
    issuer: certificate.issuer,
    valid_from: certificate.valid_from,
    valid_to: certificate.valid_to,
    subjectaltname: certificate.subjectaltname
  });
  socket.end();
});

socket.setTimeout(10000, () => socket.destroy(new Error('TLS connection timed out')));
socket.on('error', (error) => console.error(error.message));

Set rejectUnauthorized to false only for controlled diagnostics where you explicitly need to inspect an otherwise untrusted endpoint. Do not use that setting to make production trust checks pass.

PEM versus DER

Format Appearance Typical use
PEM Text with BEGIN CERTIFICATE and END CERTIFICATE markers Configuration files, OpenSSL commands, many servers and libraries
DER Binary encoding with no readable delimiters Applications or systems that require a binary certificate

Confirm the format required by the application receiving the certificate. Convert a PEM file to DER with:

openssl x509 -in example-com.pem -outform DER -out example-com.der

Convert DER back to PEM with:

openssl x509 -inform DER -in example-com.der -outform PEM -out example-com.pem

Validate the certificate before using it

  1. Check the hostname. Confirm that the intended DNS name appears in the certificate’s Subject Alternative Name extension. A certificate for another name is not the right certificate for your endpoint.
  2. Check the validity period. Inspect notBefore and notAfter against the current date and your deployment’s clock.
  3. Check the issuer and chain. Confirm that the issuer is expected and that the chain leads to a root trusted by the environment that will use the file.
  4. Use SNI. When a host shares an IP address with other sites, include -servername in OpenSSL or servername in Node.js.
  5. Check the file type. Search for certificate delimiters. Never publish, upload, or request a server private key as part of this process.

Downloading a certificate does not prove that it is valid or trusted. Trust depends on hostname verification, validity dates, signatures, and the trust store used by the client.

Common errors and fixes

Error or symptom Likely cause Fix
no peer certificate available The connection did not complete TLS negotiation, or the endpoint is not serving TLS on that port. Confirm the hostname and port, then retry with -connect host:443. Check whether a proxy or firewall is intercepting the connection.
The certificate is for a different site SNI was omitted, or the server selected its default virtual host. Add -servername target.example and use the same hostname in Python or Node.js.
Only one certificate appears The server sent only its leaf certificate. Save the leaf certificate and obtain required intermediates from the site operator or the issuing CA. Do not assume the server sends every possible chain component.
certificate verify failed The chain is untrusted, expired, incomplete, or the hostname does not match. Inspect issuer, dates, SANs, and the client trust store. Fix the chain or hostname rather than disabling verification.
OpenSSL command is not found OpenSSL is not installed or is absent from PATH. Install OpenSSL using your operating system’s package manager, then confirm with openssl version.
The saved file cannot be parsed Diagnostic text, missing delimiters, or the wrong encoding was saved. Keep only one complete PEM block, or tell OpenSSL -inform DER when the input is binary DER.
Firefox shows a warning The site may have an expired certificate, hostname mismatch, untrusted issuer, or another TLS problem. Read the warning details and inspect the certificate fields. Do not treat a warning page as proof that the certificate is safe.

Browser or OpenSSL?

Need Best route
Quick visual inspection Firefox certificate viewer
Repeatable checks in scripts or CI OpenSSL, Python, or Node.js
Several certificates from a presented chain OpenSSL with -showcerts
A file for another application OpenSSL, after confirming PEM or DER requirements

Performance, reliability, and cost considerations

  • Performance: A TLS inspection requires DNS resolution, TCP connection setup, and TLS negotiation. Keep connection timeouts finite in automation and avoid opening a new connection for every check when your client can reuse connections.
  • Reliability: Run checks from the same network conditions as the application that will consume the certificate. Proxies, firewalls, SNI, IPv4 versus IPv6, and clock skew can change the result.
  • Chain handling: Store the leaf and intermediates separately when your target software expects a specific order. The presented chain is not guaranteed to include every trust anchor.
  • Cost: Firefox and OpenSSL perform local inspection. Your costs come from the machine, network, and any monitoring infrastructure you choose to run.

Or skip the browser setup

If your goal is to capture a visual record of the HTTPS page after checking it, ScreenshotNeo provides a website screenshot API. The request is one GET call, and the API can return PNG, JPEG, WebP, or PDF output.

See the ScreenshotNeo API documentation for the available options. A basic call is:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://example.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://example.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo removes cookie banners, newsletter popups, and chat widgets before the shot. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and response headers identify the page verdict and billing result. Its MCP server lets AI agents use take_screenshot, get_page_info, and capture_pdf. The Free plan includes 1,000 screenshots each month with no card, and paid plans start at $5 for 3,000 shots.

Create a free ScreenshotNeo account to get started.

FAQ

Can I download a website’s private key?

No. A normal HTTPS connection exposes the public certificate only. The private key must remain with the site operator.

Does the certificate prove the website is trustworthy?

It proves what the certificate and validating chain assert when hostname, dates, signatures, and trust-store checks succeed. It does not guarantee that the website’s content or business is safe.

Why does OpenSSL show multiple certificates?

-showcerts displays certificates sent by the server, commonly a leaf certificate and one or more intermediates. The server may omit some chain components.

Should I save PEM or DER?

Use the format required by the software receiving the file. PEM is text with certificate delimiters; DER is binary.

Why is SNI necessary?

Many HTTPS sites share an IP address. SNI tells the server which hostname you want so it can select the matching certificate.