url="www.example.com"
openssl s_client -connect ${url}:443 </dev/null | openssl x509 -outform PEM > ${url}.pem pem_path='/home/user/'
pem_filename='somecert.pem'
sudo cp ${pem_path}/${pem_filename} /usr/share/ca-certificates
#Add the filename to /etc/ca-certificates.conf; there are various ways to do this in a script
sudo update-ca-certificates