Signed packages = _secure_ authentication of origin and not a policy (was: Should Fedora rpms be signed?)