That particular customer had set up their configuration in
such a way that the connection from Cloudflare back to the
customers origin was not passed over an encrypted link.
Is it just me, or this is Google/NSA's "SSL added and removed here! (grinny face)" all over again?
http://i.imgur.com/4p9oMTp.jpg