What's the argument against using one's own actual domain? In these modern times where every device and software wants to force HTTPS, being able to get rid of all the browser warnings is nice.
I guess the lesson is to deploy a self-signed root ca in your infra early.