You have to use that option/parameter/flag with the restic binary unless you have added your own Certificate Authority into the list of trusted CAs on the system where you run restic. So you have two options, basically.
Note that you can use e.g. Let’s Encrypt to provide certificates for your rest-server (it’s not called restic-server), instead of self-signed ones. But that’s really only useful for publically facing servers.