"Contains a Common Name (CN) or Subject Alternative Name (SAN) that matches the requested or target hostname."
... but I'm not sure if that's matching the CDN->origin request (which would make sense) or the client->CDN request (which I could understand, but I hope that's not the case)
Can anyone shed any light on the right way to interpret that?
I'm having issues with a Full (Strict) SSL connection where the hostname used by the client will absolutely not match anything in the certificate of the origin.
Similar to Full Mode, but with added validation of the origin server’s certificate, which can be issued by a public CA like Let’s Encrypt or by Cloudflare Origin CA.