So right now it would be counterproductive to mark all http pages as "not secure". But it's the long-term goal.
So right now it would be counterproductive to mark all http pages as "not secure". But it's the long-term goal.
The user will then forever ignore it (because they like that web site) and the whole exercise is wasted.
Of course relying on a provider that might cancel the free plan at any time is not ideal, but worst case you just have to revert your DNS and it's done.
They even have multiple modes, the "Flexible" one works even with no changes at your server at all. It obviously makes the CF<->server transfer insecure, but your users would still get a "green lock", if that's what you're after.
This is from their in-settings help: https://www.cloudflare.com/a/static/images/ssl/ssl.png
And then how does the renew process work?