certtool generates subject DN in reverse order
over on the IETF LAMPS mailing list, David Cooper writes:
I noticed that the attributes in the issuer and subject fields of the certificates are encoded in the reverse order of what one would expect.
In particular, the expectation is that the ASN.1 wire encoding lists the more general fields first. So, for example, "O" (organizationalName) should come before "OU" (organizationalUnit, a subset of the organization), and "C" (country) should come before "ST" (state).
(note that the visualization of the DN is typically the reverse of the wire encoding; the work done to close #111 (closed) is correct, the problem is the wire encoding)