It's easy to use our Strict mode. We'll give you a certificate for the origin for free: https://blog.cloudflare.com/cloudflare-ca-encryption-origin/
Or you can bring your own certificate from someone like Let's Encrypt.
Or you can bring your own certificate from someone like Let's Encrypt.
If CloudFlare wants to live dangerously with origin connections, fine... but give end users a way to drop the connection if it isn't secure, like our browsers would normally.