1. First of all to make these domains into a trusted domain, specific practices can refer to http://www.cnblogs.com/xioxu/archive/2009/10/12/1581538.html
2. What you have to do is import the accounts of other domains into your site. For details, refer to the http://technet.microsoft.com/en-us/library/cc263247.aspx, as per this articleArticleAfter configuring the connection, you can search for users in other domains in the site.
Note that when I started research, I saw two commands at http://technet.microsoft.com/en-us/library/cc263460.aspx,
1. stsadm.exe-O setapppassword-Password EMC
2. stsadm-O setproperty-propertyname "extends icker-searchadforests"-propertyvalue "Domain: testdc1.local, dfservice@testdc1.local, D. o7a @ BJ; domain: testdc2.local, dfservice@testdc2.local, D. o7a @ BJ "-URL https: // mospfordev
After the execution, the corresponding site cannot properly search the account, and I do not know why.
Stsadm-O setproperty-propertyname "extends icker-searchadforests"-propertyvalue ""-URL https: // mospfordev
Recovered.
Therefore, you can ignore these two commands.
3. The configuration of Kerberos is the same as that in my previous article. Http://www.cnblogs.com/xioxu/archive/2009/01/15/1376472.html