Since our packages may be maintained by many people it may get complicated for the user to add all maintainers' public keys. There should be a single public key for the whole repo.
TODO
Investigate how Ubuntu and Debian sign their official repos.
http://wiki.debian.org/SecureApt