Today I learned that cloudflare free tier universal certs do not support multilevel subdomains.
By default, Cloudflare Universal SSL certificates only cover your apex domain and one level of subdomain.
!https://developers.cloudflare.com/ssl/troubleshooting/version-cipher-mismatch/