I feel woefully out of step here. If you can create a CA that browsers respect, have you really improved on cleartext transmission? And isn't the CA is now a new attack vector?
Your typical TLS certificate is going to be more robust than your typical consumer / prosumer LAN security, and you typically have better tools (SSH certificates, 2FA, encryption at rest, etc, etc) for locking down a machine running a CA than network gear you either don't control or bought from a consumer-focused vendor.
Its a typical example of defense-in-depth. Hopefully your network is trustworthy, but if for whatever reason it becomes insecure/vulnerable you now have genuine encryption between client and server at application layer.
Is running an internal OAuth OIDC identity provider to issue signed identity tokens the same as using cleartext passwords?