For inside the lan/lab, I have my pem chain looks like:
cold storage root-ca -> offline vault qubes VM ca -> pfsense ca -> freeipa ca
I use letsencrypt for externally facing services.
Its a little bit more effort than getting things just workin' but its worth the whole lotta security you get in return. Plus it feels nice looking at a shiny green lock.