Are they using client authentication in addition to the more commonly seen server identification? Cloudflare have a post that explains why they might want that: https://blog.cloudflare.com/introducing-tls-client-auth/

hazardwarning.me.