Hmm, I should look up how that works.
Edit: https://developers.cloudflare.com/ssl/origin-configuration/ssl-modes/#custom-ssltls
They don't need your keys because they have their own CA. No way I'd use them.
Edit 2: And with their own DNS they could easily route any address through their own servers if they wanted to, without anyone noticing. They are entirely too powerful. Is there some way to prevent this?