You might check out .internal instead which was recently approved [1] for local use.
[1]: https://en.wikipedia.org/wiki/.internal
It would be great if there was an easy way to get trusted certificates for reserved domains without rolling out a CA. There are a number of web technologies that don't work without a trusted HTTPS origin, and it's such a pain in the ass to add root CAs everywhere.