From Fedora Project Wiki
- markmc Yay! (is that helpful? :-)
- toshio So what happens when this single signing key is compromised?
- User:jkeating We create a new key, and start resigning things for the active releases. Ideally we'll be signing repodata by then too with keys that do change per release which can mitigate issues with existing repos.