TLS server certificate trust

Exclusively TOFU? What should a client keep? The entire certificate? Fingerprint? Public key field?