This is my proposal for a signature verification policy to resolve issue 610. It relies on the pull request https://src.fedoraproject.org/rpms/fedora-rpm-macros/pull-request/1, which makes the code templates simpler than in the proposal in the wiki. I have expanded the policy on how to obtain the keys, as that's the step where everything depends on the vigilance of the packager.
This is my proposal for a signature verification policy to resolve issue 610. It relies on the pull request https://src.fedoraproject.org/rpms/fedora-rpm-macros/pull-request/1, which makes the code templates simpler than in the proposal in the wiki. I have expanded the policy on how to obtain the keys, as that's the step where everything depends on the vigilance of the packager.