Just noticed that (at least some - e.g. CentOS-5 kernel-debuginfo, kernel-debuginfo-common, aspell-debuginfo) debuginfo packages are not signed. Started to file a bug entry, but don't know if it is merited. Is the intent to have these packages signed? The Debuginfo Wiki page shows "gpgcheck=1".
http://wiki.centos.org/AdditionalResources/Repositories/DebugInfo
Phil