This would solve Troy's issue with his own site, too - his hoster serves it with a * .ghost.io certificate. If he could configure CloudFlare to only accept certificates that match troyhunt.ghost.io, that would be a lot safer.
I have the same use case with GitHub pages -- https://www.glowing-bear.org is Full SSL in Cloudflare, but I can't switch it to Full (strict) because the upstream certificate is for * .github.io