Name, IP address, and authentication all come together to establish the trust to provide the certificate. Plex.tv is guaranteeing that this IP address & host is who it claims it is. That’s the purpose of a certificate, isn’t it?
Would you let just anyone have trusted, secure, access to your communication which will contain personally identifiable information (username & password)?
But why we limit in the fact that the determined ip address (which will out to be inaccessible) cannot be indicated differently for the creation of the certificate?
after all, I would just like to indicate using DNS the correct IP, providing the address on which the actual server responds, which will already be authenticated. and Plex.tv can check now the server to generate the new certificate on the new IP