You want the PDC Emulator in the root domain to be using NTP and all other DCs to be using NT5DS to sync time. As long as everything is within 5 minutes of each other Kerberos (within the forest realm ...