yep. if you trust the server you are getting the data from, then you need their package key. once you have it installed all software listed as being from them will be recognised as such by the rpm subsystem. if someone tries to deliver a dodgy rpm containing, for example, a rootkit pretending to be from the fedora project the keys will not match and you'll be protected as it will reject the package.
|