Hi, You will need to match a few things.
1. encryption key
2. agent keys(and session ticket key)
3. user store name
4. userstore DN structure.(and userdn)
So you should make it look like it is the same(?) env.
the keystore, it should be replicated between your a.com and b.com
And your a.com PS(r12) should generate agent keys.
Your b.com PS(r12.52) should have "EnableKeyUpdate=1" in the registry.
This forces your b.com PS to poll the keystore for changes.