Do you handle Cloudflare and CDN SSL?
Yes. Cloudflare (and CDNs like Fastly) add a second SSL layer: the cert at the edge between the visitor and the CDN, and the cert at the origin between the CDN and your server. The common mistake is using Cloudflare’s “Flexible” mode, which leaves origin traffic unencrypted and can cause redirect loops. We configure Full (Strict) mode with a valid origin certificate, so the connection is encrypted end-to-end and there are no loops.