You can use a public CA like LetsEncrypt then. Exposes you to the certificate log but you should be secured already anyways. Just have to use the DNS challenge (unless you wanna poke a hole for certbot) to grab it
So much simpler for everything to revert to client only mode and route all messages through a server 3000 miles away. Until they pull the plug and nothing works at all.
So... lets... make the tech that powers it not suck, so we can stop with all this analog business.
The steps for an intranet or regular domain is exactly the same if you use the DNS challenge as the web server is no longer involved regardless.
The DNS methods we already mentioned does not involve any of that - just a simple zone file change or a few clicks in a web UI to add a new record.