Cloudflare's universal certificate covers example.com and *.example.com only — a second-level subdomain such as api.staging.example.com is not covered, so the name never matches.
Cloudflare's universal certificate covers example.com and *.example.com only — a second-level subdomain such as api.staging.example.com is not covered, so the name never matches.
Either flatten the hostname to one level, or buy Advanced Certificate Manager and add the deeper wildcard. Confirm the SSL/TLS mode is Full (strict) so the origin certificate is validated too.
Cloudflare has its own failure mode, but ERR_CERT_COMMON_NAME_INVALID has a wider set of causes. The most common one overall is: The certificate covers the apex domain but not the www hostname, or the reverse.
Reissue covering both names, or redirect the uncovered hostname at the DNS/HTTP layer before TLS is negotiated — which is not possible over HTTPS, so the certificate must cover it.
The SSL check reports which names the served certificate actually covers, which is the whole answer to this error in one line.
Cloudflare's universal certificate covers example.com and *.example.com only — a second-level subdomain such as api.staging.example.com is not covered, so the name never matches.
Either flatten the hostname to one level, or buy Advanced Certificate Manager and add the deeper wildcard. Confirm the SSL/TLS mode is Full (strict) so the origin certificate is validated too.
The certificate is valid and trusted, but it was issued for a different hostname than the one in the address bar. The classic case is a certificate covering example.com being served for www.example.com.