hi,
if you try to create a subca for pfsense from a windows pki this command is key:
certreq.exe -submit -attrib "CertificateTemplate:SubCA" subca.csr
It will take the csr from pfSense and use the SubCA template on the signing on the windows root ca.
Hope this helps some people.
Blex