> In the future, Fedora might wanna have multiple keys.
If Fedora packages were signed by multiple independent signatories, yum could be designed to accept (for instance) only packages signed like this:
- Fedora key
- at least 2 other keys from independent signatories
or
- 5 keys from independent signatories
In that case, a compromise of a single key would be easily avoided, as long as you had enough signatories in the pool to make up the numbers (and with vast number of people involved in Fedora, this is definitely possible).