Protecting Auth0 Domain with WAF (Take 2)

I have found this FAQ: Protecting Auth0 Domain with WAF
It provides no information whatsoever.
Can you provide more information about

  • how to configure the WAF for custom domain versus alias cname
  • any implications on the self-managed certificate option for a custom domain
  • any implications on SSL termination
    thank you.