Certificate problems in the path.
THE TWO CERTIFICATES
Visitor to Cloudflare, which Cloudflare provides. Cloudflare to us, which is ours.
Both must be valid. An error can be in either.
ERROR 526: INVALID SSL CERTIFICATE
Full (strict) is set and our certificate is not valid for that hostname.
Run AutoSSL in cPanel covering every domain and subdomain.
ERROR 525: SSL HANDSHAKE FAILED
The connection between Cloudflare and us could not be established securely.
Usually a missing or misconfigured certificate at our end.
A CERTIFICATE WARNING IN THE BROWSER
Cloudflare's certificate should cover your domain and one level of subdomain on the free plan.
A deeper subdomain needs either a paid plan or DNS-only mode for that hostname.
AUTOSSL FAILING
Covered separately. Usually Cloudflare intercepting the validation request.
THE RELIABLE SEQUENCE
Set records to DNS only Run AutoSSL and confirm it succeeds Set records back to proxied Set SSL mode to Full (strict)
That produces a correct configuration at both ends.