A cross-certificate is a digital certificate issued by one Certificate Authority (CA) that is used to sign the public key for the root certificate of another Certificate Authority. Cross-certificates provide a means to create a chain of trust from a single, trusted, root CA to multiple other …

Security issues. In a CA based PKI system, the CA must be trusted by both parties. This is usually accomplished by placing the CA certificates in a whitelist of trusted certificates. For example, web browsers developers may use procedures specified by the CA/Browser Forum, or a private CA's certificate may be placed in the firmware of an embedded system.

and that root certificate is automatically pushed into machines when they are joined to the domain; You can find this domain certificate in your Trusted Root Certification Authorities store: e.g. our domain's self-signed cert is valid for 50 years.