Added integrity checking for fetched archives via signed digests. New pubkeys.conf file allows configuring keys to trust. The private counterpart of the installed public key will of course need to live on our binary building server.

1# Downloaded archives will only be used if they can be verified by a public
2# key listed here. Use full paths, one per line.
6# To distribute archives of your own, you need a key pair generated like so:
7# openssl genrsa -des3 -out privkey.pem 2048
8# openssl rsa -in privkey.pem -pubout -out pubkey.pem
9# Then sign the archives like this:
10# openssl dgst -ripemd160 -sign privkey.pem -out archive.tbz2.rmd160 archive.tbz2
