Certificate for public IP without domain name

My1 reverse lookup TXT entries are possible.
If you own an /24 or /16 or /8 than you have the mathing “.in-addr.arpa” zone.
For different CIDR there are two options:
a) Provider point an NS for the full reverse entry to use (<24) or for the next smaller sub zone.
b) you can ask the IP provider to ad the TXT record.
But than the record should not be dynamic. For example it contain the Checksum of the public key.
And you need than to prove than you can sign an nonce with an private key that match the anounced public key hash.