Yes. Traffic from and to the webserver is encrypted so it can't be hijacked by someone (so called man-in-the-middle attack). Most websites don't need it. It is mostly used for pages that acquire or display sensitive information, such as login pages.
I guess Kalcor turned this CF SSL on by accident -> Traffic from CF to SAMP's webserver is still unencrypted.