You aren’t proxing for that domain, so it is using the origin certificate, which is invalid. You need to get an SSL certificate. You need to get an SSL certificate for your server that works with Cloudflare, either something like Let’s Encrypt or an Origin CA certificate then you can enable for the record.
No, you can’t use Advanced Certificates as they sit on Cloudflare and you don’t have access to the private key. If you don’t want to proxy the domain, then you need to use something like Let’s Encrypt