Is there a reason you need to use OD. In my experience is it just simply a "bag of hurt".
You have to bind the client Macs to both AD and the OD server (that is bound to AD), assuming this OD Server is also correct and stable.
If the OS X client loses only one of the AD or OD bindings, the Mac cannot log in. That is ridiculous.
Why would a Mac admin or anyone want to introduce these dependencies.
I have seen it a ton of times.
And then there could be issues with Kerberos.
If it was me, and I had to bind to AD. Just use Apple's built in AD plugin in (Directory Utility), by itself.
There is very little reason to use OD in AD, unless one wants Managed Prefs. Are you kidding. Apple's Managed Prefs are more suited for a school lab of 50 Macs or so, they are global and pretty weak. I see no use for it. If you want true policies (MSs Group Policy) Centrify is pretty good.
AD binding does work in 10.6.8 in this manner pretty well.
But as I have mentioned here, in 10.7 AD binding was broken on shipping of 10.7, it seems to be working once again as of 10.7.2.
I am trying to to figure out for the life of me how AD binding of a Mac is even relevant anymore. It makes no sense to do it. We no longer do it, why.
If users need to get to areas on the network, shares, etc, they simply enter their AD credentials.
If one really needs AD binding for some reason (I still cannot fathom), consider using Centrify Express, which works pretty well, at least they are on top of it and are proactive about it always working.
It seems obvious to me AD binding is simply not a priority at Apple, it never has been, and is it even relevant today.