> The answer is local acme with your router issuing certs for your ULA prefix or “home zone” domain.

That would be nice. But most people don't have a router running an ACME server.

It should become a thing