PSA: You don't need a private CA for internal SSL certificates.
The CA doesn't connect to your server. It checks a DNS record. Your server can be completely unreachable from the internet.
https://www.certkit.io/blog/private-pki-internal-infrastructure
#PKI #ACME

You probably don't need private PKI for internal infrastructure
Most teams assume internal infrastructure needs a private CA. It doesn't - and skipping it saves you from a maintenance burden that never fully works anyway.
CertKit SSL Certificate Management