How does a cross-forest trust work?
A cross forest trust consists primarily of a shared secret (associated with a trustedDomain object) between forests, and some mapping information which enables DCs to refer requests with certain UPN or SPN suffixes to the appropriate domain. See the section on cross forest logon for more detail. Also of note is that in addition to the information needed to issue Kerberos referrals, a forest trust can be leveraged like a downlevel trust (NTLM) when needed.