I am running 10.6.8 server, but I am having the exact same problem that you are. Same setup, and same configuration. I found this article which may help you out (link below), it might be an issue with the way your bind to AD is set up through directory utility. I tried this and it did not work for my setup, but it is written for 10.7 server, not 10.6 so maybe it will help you. Has anyone else run into this, or gotten it to work correctly?