Sometimes you need the Certificate of a remote host. The following command will help.

root@ieibgmgmtvcsa01 [ ~ ]# openssl s_client -connect ben-on-vms.com:443 < /dev/null | openssl x509 -in /dev/stdin 
depth=2 O = Digital Signature Trust Co., CN = DST Root CA X3
verify return:1
depth=1 C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3
verify return:1
depth=0 CN = ben-on-vms.com
verify return:1
DONE
-----BEGIN CERTIFICATE-----
MIIFaTCCBFGgAwIBAgISBJrd2DU2uCmu2pAabO/b5qqLMA0GCSqGSIb3DQEBCwUA
MEoxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MSMwIQYDVQQD
ExpMZXQncyBFbmNyeXB0IEF1dGhvcml0eSBYMzAeFw0yMDAxMjgxNTM0MTdaFw0y
MDA0MjcxNTM0MTdaMBkxFzAVBgNVBAMTDmJlbi1vbi12bXMuY29tMIIBIjANBgkq
hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyqAAwnhv1D4oTgQVRGzm6prZBcWAhHIu
5GJAeL92XI+n+SeZ9uNIUgLB26/R2LOvRlTet2pAWhKy00UlK7eWH+uKNQ/ya2WW
In4SRytIhMslVFIw4ISSDuWqxSZ+CsUNLIkQImf+4eYbI8iPSDFiXiKhsjC2nTK7
sXG0FUNlitIYt1PXwKEW3vfs2nUcMVHMLiPJ7sQcc1CZFfSu1qrvEskg+yIJEVjn
v2hi30asP/3WoH/pYcqqALgqXb0/Fzx0Wh3/BzyhcZPsYl0Elh1PeSOe9C6AQ5/Z
VlcAXUYHgiHE4CnUousSZ+E1ggENUK1tbEjIKw/7dp855GYB+l1T0wIDAQABo4IC
eDCCAnQwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEF
BQcDAjAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBSAUSqFBGIdFn+A95n3FKuo1BCd
5DAfBgNVHSMEGDAWgBSoSmpjBH3duubRObemRWXv86jsoTBvBggrBgEFBQcBAQRj
MGEwLgYIKwYBBQUHMAGGImh0dHA6Ly9vY3NwLmludC14My5sZXRzZW5jcnlwdC5v
cmcwLwYIKwYBBQUHMAKGI2h0dHA6Ly9jZXJ0LmludC14My5sZXRzZW5jcnlwdC5v
cmcvMC0GA1UdEQQmMCSCDmJlbi1vbi12bXMuY29tghJ3d3cuYmVuLW9uLXZtcy5j
b20wTAYDVR0gBEUwQzAIBgZngQwBAgEwNwYLKwYBBAGC3xMBAQEwKDAmBggrBgEF
BQcCARYaaHR0cDovL2Nwcy5sZXRzZW5jcnlwdC5vcmcwggEFBgorBgEEAdZ5AgQC
BIH2BIHzAPEAdwCyHgXMi6LNiiBOh2b5K7mKJSBna9r6cOeySVMt74uQXgAAAW/t
AOhuAAAEAwBIMEYCIQCPdJOxNPRekbIT0lzA9hiWg95Q4jeH8kzp1uFij7G76wIh
AJijd5Pa5i9vL40h27RQNlBxaUcBQJBIFMplPDUjSfGQAHYAb1N2rDHwMRnYmQCk
URX/dxUcEdkCwQApBo2yCJo32RMAAAFv7QDo9AAABAMARzBFAiAJKayGpEqp6aez
SK73HFBvJWP/ms/5QKZGUv3/Z9zpKQIhAIVJv7BHk4CXVP/oiCFzWHPJKyZwVPBr
LovBrepF3Y3uMA0GCSqGSIb3DQEBCwUAA4IBAQBl+/by7DxVneXF2dWODLU+d7mX
/S1+70kNbcmqJhmt0QIHxe2QI7zNNI+fHffViU8Tolj47pCPG5RHpOdojTYBLP6D
qzHcCAez4JmCFkX52Uqpc5rq86vT0m/svN4/tehz8krtvAK326HADtrOWHW3wQjZ
i+IyRw/k+fpbm/AD2zL1teeOje/uKNZeeF8eNvvBI/gihNF/lARRLH53j5CPWPDY
hJGkhkW51647Pr9lpuhtmlclYKvG5MQWQloQHUwRbiwmW3CaWRinehbiH60paP3L
+y3jfoTjJTSIEPM8W0yqtLbVocbk/cjT/UMhCSDTmxvHBXoqy3ztO0t7ODEw
-----END CERTIFICATE-----
root@ieibgmgmtvcsa01 [ ~ ]# 

So now you can do what ever you need with the certificate.