As mentioned, domain security uses digital certificates to secure the SMTP channel between two organizations. As such, a certificate trust between the two organizations needs to be in place. This can be done by using publicly trusted certificates or by exporting and importing the certificates used for SMTP into both organizations.
The bottom line here is: each Exchange server has to trust the certificate installed and assigned to the SMTP service on the other organization's Exchange server. Besides establishing this trust, it is important to make sure that the certificate common name is the same as the name that Exchange provides in the HELO/EHLO greeting.
Then we specify for which domains we will be sending and receiving ...