First of all, you don’t even need an SSL certificate on our hosting. Just configure Cloudflare to use “Full” SSL mode and not “Full (strict)” mode, and your website will work right away, using fully encrypted connections, without any further configuration required.
If you do insist on using strict SSL mode, you can get an Origin Certificate from Cloudflare and upload that to your account.
Using a “real” SSL certificate on your hosting account should work. However, Cloudflare also sets up records on the _acme-challenge subdomain to they can obtain SSL certificates for your domain. Those (hidden!) records from Cloudflare take precedence over the CNAME record you have configured. Our DNS check sees those records, which are the “conflicting records” warning you get.