Correct me if I am wrong but you generally won't find a specific cownload option for the certificate directly from Azure. This is because Cosmos DB uses SSL/TLS to secure data in transit, and the connection uses the certificates trusted by the underlying system or development framework you're using.
Why ? Just because most client libraries and development environments are configured to trust a set of well-known CA certificates that are included with the operating system or framework. For Windows Server, this means the CA certificates trusted by Windows should automatically be trusted by your application, assuming you're using standard libraries that rely on the system CA store.
If you mean exporting the certificate here is an old thread :
https://stackoverflow.com/questions/77808551/cosmos-db-emulator-container-cant-export-certificate