It's worth noting that an IETF Working Group is being formed to try to address the issue of TLS certificates on local networks.
https://datatracker.ietf.org/wg/settle/about/
It don't know what they might come up with. It's a tricky problem at this point, but at least somebody's trying.
I'm roadmapping how Dropserver can be useful on a local network with minimal technical intervention, and the TLS problem looms big.