I have employed edge certificates for my domain, but have made changes so that my sub domains get their certs from Let’s Encrypt. This is due to the sub domains sending out mail and the need to validate their IPs directly, rather than the proxied IP from Cloudflare. I would like to change the edge certs, so the domain is protected. Can I reject the current certs and then just issue new certs for the domain only, or should I just abandon using Cloudflare certs and just have Let’s Encrypt issue a cert for the domain itself.


To be able to select the Certificate Authority that issues your Cloudflare Edge certificate, you will need to look at subscribing to: Advanced certificates · Cloudflare SSL/TLS docs

