No need for special registry scripts, these settings map to existing GPO options:
Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options
Microsoft network client: digitally sign communications (always)
Microsoft network client: digitally sign communications (if server agrees)
Microsoft network server: digitally sign communications (always)
Microsoft network server: digitally sign communications (if client agress)
Network security: LAN Manager authentication level
I just set these to see if it will help with my problem:
http://forums.procooling.com/vbb/showthread.php?t=13134