You can do IP based certificates, I have one's generated for pfsense/opnsense and openwrt devices.
I generate using the wizard in pfsense as I am lazy, that also stores them for me as well master copies, and have the authority trusted on my PC and laptop.
As for the TLS 1.1 only thing, this is why I stopped using proprietary firmware devices. All the planned obsolescence of them.