nano add_certs.sh
#!/bin/bash
#
if [ -z "$1" ]; then
echo "provide a domain as an argument"
exit;
fi
d=`date +%Y-%m-%d`
p=~/$1$d.pem
f=~/$1$d.cer
touch $f
touch $p
# path added -- brew openssl....
# echo 'export PATH="/usr/local/opt/openssl@1.1/bin:$PATH"' >> ~/.zshrc
# get pem file
openssl s_client -showcerts -connect "$1:443" -servername $1 </dev/null | sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' >$
# https://stackoverflow.com/questions/13732826/convert-pem-to-crt-and-key
openssl x509 -inform PEM -in $p -outform DER -out $f
echo "new certificate"
./add_certs.sh www.googleapis.com