Earlier quoted context omitted.
I don't know why there is still no standardization for advertising/providing CA services for local networks. How difficult would it be to just put local ACME endpoint to DHCP options?
But then what’s the point? How is it more secure to have anyone get a server cert automatically without credentialing. Not to mention training users to trust all the BS local CAs popping up now that can then MITM traffic. As a user, I don’t want local networks setting me up to make me recognize their CA services. At first I liked SSL everywhere, but now I’m seeing a lot of hacks that are going to make SSL less useful…
You say that as if users don't already mindlessly dismiss most warnings already. I'm not convinced this would be that big of a difference from the current system.