I tested it just now. Universal cert for proton.ad.gt is in Pending Validation state.

I have a partial CNAME setup: https://developers.cloudflare.com/dns/zone-setups/partial-setup/
I already have a few subdomains successfully configured with Universal certificate.
Two days ago, I tired setting up another one: proton.ad.gt. Unfortunately, the TLS has been in Pending Validation state since then. The request is for a DigiCert certificate.
Backend seems configured correctly, I am not using wildcard certs in the backend, just a regular AWS cert with a few simple common names.

To make matters worse, today, another ad.gt subdomain that was configured about a year ago started reporting that the Universal certificate is in pending validation status. The old cert was from DigiCert, the new request is from LE.

I have no DNSSEC enabled, ad.gt is configured in AWS.

Pending Validation

  1. Avoid using wildcard certs in the backend
  2. Ensure that I have backend responding on both HTTP and HTTPS
  3. Since the validation challenge is HTTP, I have added the well-known request to the backend, even though I should not need to do it
  4. I have checked that I am not using DNSSEC that could potentially block the certificate issuance.

  1. Visit the site or check the Edge Certificates panel

If you navigate to the SSL / Edge-Certificate menu in the Cloudflare dashboard, you will see a very prominent warning:

What exactly you need to do is outlined in the linked article, it depends on your kinds of records (wildcard or not), whether you use Advanced Certificates and some other configurations.

From the pages you suggested:

If your domain is on a Partial setup, Cloudflare will automatically complete HTTP-based DCV on your behalf.

