We're using MS-CHAPv2 with PEAP (with WPA encryption) so that the user's AD credentials combined with the user certificate will log them in over the wireless with full access to their network shares...