I think it is different now.
I had big difficulties with Lion Server. Lately, OD and AD kerberos worked side by side, without turning off OD kerberos! I think it is enough to join the server with the directory utility, either from System Settings via User Panel or via SERVER.APP, there is a menu to open it up.
In my config, an update to ml from 10.7.4, all settings were kept. I think there is one big change now: AD users are just listed in server.app in users (dropdown menue to select the kind of users) and are no longer imported as augments into OD. (the update brought them as augments into ML, but could not find any reason for now, so I removed the augments)
Kerberos auth seems to work side by side. So I can login to my mac with my users credentials.
It is just important to have the search orders in directory utility setup correctly. And I reduced them to my domain and not the whole forest.
Perhaps an additional
sudo dsconfigad -enableSSO
helps.
So I would try:
1. setup ML
2. join to AD via directory utility and check search order and AD server to search for (AD as far on top as possible) and make settings, (german system, check the admin group and add the german group in case)
3. try to login with AD credentials
4. in case when logged in make admin via systemsettings Users
5. install server.app
6. check user tab for external directory via dropdown menue
7. check if login still works
8. check some service like cal, wiki or so and if it is possible to login
9. in case it does not work try sudo dsconfigad -enableSSO in terminal.
10. turn on open directory, which makes a default group in server.app groups
11. check via terminal and sudo serveradmin settings dirserv if the AD is listed and the main kerberos server
I have no Idea, if one has to make any settings like in Lion for some services to work with AD, as all work for me right now.
Only one thing is strange: I had Open directory setup with my SSL certificate and tried to turn it of before upgrading, which left my OD not working. As I have not to many users right now, I dismissed my OD master and turned it back on without a SSL cert.
But, it stops when i try to set up the certificate afterwards.
Hope that helps somehow.
Best
H