Could be. First shipped when? Last patch by microsoft was when? The certificate at the root of your cert chain was issued when?
You can do your own homework
But like I said, that can be fixed by putting the public key of the CA root cert in your plugin, and give that somehow to curl to be trusted.
But ultimately you want to see the verbose output, so you know a bit more than "SSL handshake failed"
