Actually it's possible to use the CA system on a closed LAN.
A) register a domain. For example company-lan.com.
B) assign each server on your Lan with a name and (local) address. Eg, daisy.company-lan.com, resolving to say 192.168.1.1
Clearly this address is only useful when used inside your lan.
C) provision certificates for this address using the DNS-Challenge approach rather than the HTTP-challenge approach.
(Bonus tip; using a DNS provider with a good API makes the process automateable).