Is there some confusion here between partitioning CRL's by certificate attributes, which doesn't seem to be supported, and assigning new certificates to CRL Distribution Points, which seems to be an internal function of the CA with few rules except that the ID of the CRL Distribution Point must go into the appropriate extension?