Yeah that alternate name is not the same as SAN in the cert.. That is so you don't get rebind or http_referer problems..
IP would not be valid there ever..
If you want to do rfc1918 IP in your cert, you would have to have your own local CA sign the cert. There is no public CA that would sign a cert with rfc1918 IPs in them..
I use san for my rfc1918 address in my web gui.. Where did you get that cert? From a public CA, or did you create the cert with CA you have running on pfsense?