CF Requests your origin over HTTP, your origin responds with a redirect to HTTPS, the client follows, makes another request to CF, Cf requests your origin over HTTP.... etc
edit: Oh you're getting a 301 back and forth, hmm, I wonder if that could be Always use Https + off/no encryption