[CentOS-devel] Some way to validate SIG repo repodata (via HTTPS or GPG-signed repomd?)