Heyia ! I battled a few weeks to get my own mini-ca to work in my own lan (green padlock, no warning) while a lot of people would argue that it doesn't add much security wise and give a fault sense of protection, it still encrypts your communication in your LAN.
Normally you will give NGNIX a "server" certificate, the one that will be tested against your rootCA installed on your computer/laptop for each service (or a wildcard domain cert).
If you want to see if your communication is encrypted and secure, give wireshark a try and look if your communication is in plaintext or encrypted gibberish !
Also If you want I got some good documentation on how to create your own mini-ca in your homelab !