openssl s_client -connect foo.badssl.com:443 -servername foo.badssl.com
openssl s_client -connect foo.badssl.com:443 -servername foo.badssl.com | tee /tmp/logcertfile
openssl x509 -in /tmp/logcertfile -noout -text | grep -i "issuer"
curl --output sectigo.crt http://crt.sectigo.com/SectigoRSAOrganizationValidationSecureServerCA.crt
openssl x509 -inform DER -in sectigo.crt -out sectigo.pem -text
PORT=3000 ROOT_URL=https://prod.domain.com NODE_EXTRA_CA_CERTS="/home/admin/sectigo.pem" node main.js