It looks like there are two possible values for the PEM header in CSRs.
Certstrap currently expects the new style (used by OpenSSL) of "CERTIFICATE REQUEST".
The Microsoft certreq tool generates certificate requests with the old style "NEW CERTIFICATE REQUEST" (see https://stackoverflow.com/questions/28628744/is-there-a-spec-for-csr-begin-headers for a discussion of this).
Would it be possible for certstrap to support the style used by certreq so these do not need to be modified prior to use?