I've added a workaround to the OpenSSL 1.0.2 and master branches: if you use -nocerts and -certfile you can control the order of certificates in the PKCS#7 structure.
Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org ______________________________________________________________________ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager majord...@openssl.org