I think that you are mixing a lot of different concepts.
ACS 4.2 can integrate with 2003 or 2008 for AD authentication of users.
If you talk about CA verification (like with EAP-TLS), then the domains don't matter at all.
If your father domain is the "father" CA as well that issued the child domain CA, then all the certificates issued by the child domain will be trusted as well as long as ACS trusts the root.