I'm sure, that you have to add the hierachical AD name to the person document of your users, that's the only way, that the redirect database may find the user mailfile.
I don't know your complete environment, perhaps you must delete the http password in the person document, then the login goes against AD (through Directory Assistance).
Regards
Chris