openssl is a command line tool that:
With the s_client don't forget to use sni
openssl s_client \
-connect server.example.com:587 \
-servername server.example.com # the sni
The certification and ca are located at /etc/ssl/certs
Update of the CA happens via a package.