You need two SSL certificates for end-to-end encryption. If your origin certificate expired, maybe regular “Full” SSL will work since it’s not necessarily checking for a valid SSL certificate.

That Dedicated Cloudflare certificate is on the Cloudflare proxy server, and that’s what your visitors will see. It’s still good to have some certificate on your server. You could go with a Cloudflare Origin certificate that’s only valid when you’re using Cloudflare:

