Short version, and Deebster’s got the shape right: use a DNS-01 challenge. You prove domain control with a TXT record instead of serving a file over HTTP, so the hostname never has to be reachable from the internet. That’s what gets you a real Let’s Encrypt cert for a LAN-only name.
Mine’s acme.sh issuing a wildcard for *.lan.michaelharley.net via my registrar’s DNS API (Porkbun), with a deploy hook dropping it where Caddy reads it. Caddy’s own Cloudflare plugin is simpler, I just already had acme.sh. Local DNS is a wildcard rewrite on my router.
michaelharley@infosec.pub
Deebster@infosec.pub 9 hours ago
I’m not OP, but I use Caddy as a reverse proxy, which generates a wildcard TLS certificate via their Cloudflare integration (who host my DNS). At some point I’ll move off Cloudflare but I never intend to host my own DNS (or email).