No authoritative reference; only my own experiences. Like you, I tried making this work and found that it was not possible.
My hunch is that WDS relies on using the WPA/WEP password to authenticate between multiple base stations and that, with WPA2 Enterprise and no single password, there is no way for the base stations to authenticate to each other. They would need an account to be authenticated via RADIUS, as well as the ability to accept a certificate - neither of which is within the range of capabilities of Apple's implementation of WDS.