J12t (npub1a32…ea5z) your device needs to trust each and every CA, and it's either or
Either you trust every single cert issued this way, or none of them
DANE exists and would be possible to aetup on your local network though (maybe, everything is bad at DANE)
en.m.wikipedia.org/wiki/DNS-ba…
