If you can’t accept inbound http traffic then you use DNS verification and if you never contact the internet then no public cert could work for you.