Hello,
It is recommended to reset the krbtgt account password in the child domain first, which minimizes the risk of potential problems propagating upward to the parent domain. For each domain, you need to perform two consecutive password resets on the krbtgt account. The second reset ensures that any possible compromise with the old password is invalidated.
After completing two password resets in the child domain, you should wait for replication to complete and the Kerberos ticket lifetime to expire. The default ticket lifetime is 10 hours, but it is recommended that you wait longer (such as 24 hours) to ensure that any cached tickets expire, and the changes propagate correctly.
After ensuring the stability of the child domain after the reset, you can proceed to perform two consecutive password resets on the krbtgt account in the parent domain.
I hope the information above is helpful.
Best Regards,
Yanhong Liu
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.