IP addresses must be accessible from the internet, so still no way to support TLS for LAN devices without manual setup or angering security researchers.
I mean if it's not routable how do you want to prove ownership in a way nobody else can? Just make a domain name.
One can also use a private CA for that scenario.