About this question
In X.509 architecture what are the uses of cross signing certificates from other hierarchies? Does it just expand trust? So from the answer, I am assuming that if CA3 is cross-signed by CA2 (from another hierarchy) and CA1 (a parent in its own hierarchy) whose private key is used to encrypt the authentication hash in the certificate of CA3?