Client Authentication via cloudflare to CaddyServer

I managed to get it going, but when initially connecting to my site I was getting privacy concerns from my browser that it couldn’t resolve the origin-pull-ca.pem

What I couldn’t understand from the process was where the root of the certificate would come from for my private cert. I ended up merging my downloaded private certificate and the origin-pull-ca.pem into one p12 file and loading that on my device.

Was that the correct procedure, or should I have followed some other procedure to create my client certificate?

