Just troubleshooting an issue here...I have two forests....with top level domains...DomainA1 and DomainB1...
The Cisco ACS is installed on a server inside DomainA1..
Users like JohnSmith.DomainA1 and JaneSmith.DomainB1 are able to authenticate off the Cisco ACS Server, which in turn passes this to the Windows AD just fine.
Users within the child domains of DomainB1 fail authentication....so a user like DomainB1.ChildDomain.MarkSmith...
I've confirmed that we have a trust between the two forests (ie DomainA1 and DomainB1)..
Does that carry over to the child-domains of the other forest (DomainB1)?
Do I need a trust between the specific child-domains to the domain that the Cisco ACS server is installed on?