Warp client with Horizon

We are implementing zero trust with our vmware horizon server in order to restrict who can see our web portal and login. We are stuck with the process of updating the certificate on our horizon and UAG servers. We typically get our certificate and CA Cert from GoDaddy and bundle these all together with a newly generated private key. What is this process using the certificate provided by Cloudflare? Would this be a client certificate or an origin certificate. Then with the certificate and key file received from Cloudflare what is the CA Certificate we can use in order to bundle these together and use?