> The only wireless security I put any real trust in is WPA2 Enterprise with 802.1x certificate-based authentication specifically.
802.1x with a certificate for Radius server (TTLS mode, which simply layers the plaintext password via TLS) and plain passwords for users is also good enough.