Yeah I don't expose Jellyfin over the Internet, so it doesn't matter for me, and wouldn't work at all over WAN (unless VPN'd to home network).
Also, it's all reverse proxied, and there's nothing preventing having two Jellyfin hostnames, e.g., jf-local.mydomain.com and jf-public.mydomain.com.
I just use Let's Encrypt with a wildcard domain
same certs for public and private facing domains. I'm sure this isn't best practice, but it's mostly just for me so I'm not too worried :)