I'm not sure the alternative is sef-created RootCA. (But perhaps I don't understand the underlying case.)
To me, the alternative is just a LE cert. Can do wildcards via DNS challenge.