Finally, I could make Airport Extreme and Airport Express to run in the WPA2 Enterprise mode. Here is how it works:
go to the shell
type: vi /usr/local/etc/raddb/eap.conf
uncomment all command lines within the brackets of the following protocols: tls and ttls (DO NOT uncomment the commentaries)
save the file
restart FreeRADIUS in the Services Menu of the Browser.
Configure the Airports as Clients on pfSense/Freeradius and configure the wireless settings on the airport as WPA2 Enterprise with the Radius settings you just configured (secret key, etc.)
Connect to the Airport via your Powerbook and choose "TTLS - PAP" in the 802.1X Configuration menue.
Everything should work fine for now, except that you get a certification warning.
Note that this help is not the safest way to use. At least you need to create new certificates later and place them in /usr/local/etc/raddb/certs