# IE11 on Win7 handshake\_failure

**URL:** <https://community.letsencrypt.org/t/ie11-on-win7-handshake-failure/135078>\
**Category:** Help\
**Created:** [October 2, 2020, 11:46am UTC](https://community.letsencrypt.org/t/ie11-on-win7-handshake-failure/135078 "2020-10-02T11:46:10Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [October 2, 2020, 12:34pm UTC](https://community.letsencrypt.org/t/ie11-on-win7-handshake-failure/135078/4 "2020-10-02T12:34:04Z")

</div>

> [@Ezyweb-uk](#):
>
> and the ssllabs client test indicates TLS 1.2 (and 1.1 and 1.0) as supported.

Ah, thanks, checked, good to know.

But your setup can't work:

That's

| TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256 (0xc02f) ECDH secp521r1 (eq. 15360 bits RSA) FS | 128 |
| --- | --- |
| TLS\_ECDHE\_RSA\_WITH\_AES\_256\_GCM\_SHA384 (0xc030) ECDH secp521r1 (eq. 15360 bits RSA) FS | 256 |
| TLS\_ECDHE\_RSA\_WITH\_CHACHA20\_POLY1305\_SHA256 (0xcca8) ECDH secp521r1 (eq. 15360 bits RSA) FS | 256 |

too limited. Windows doesn't support GCM with RSA and no Chacha20. So there is no matching Cipher suite.

> [@Ezyweb-uk](#):
>
> TLS\_ECDHE\_RSA\_WITH\_AES\_256\_CBC\_SHA384

Yes, you have to use the deprecated CBC, so you will have a Grade B.

---

_[View the full topic](https://community.letsencrypt.org/t/ie11-on-win7-handshake-failure/135078)._
