In our experience with osg-incommon-cert-request, the InCommon IGTF certificate service ignores almost everything in the DN of the CSR, other than the /CN portion. All of those other values asked for in osg-cert-request are automatically filled in based on the InCommon configuration for the particular institution. It could be worth testing that and likely simplifying osg-cert-request.