Attempting to check the GPG signature on a machine that I hadn't
previously installed gnupg onto, I realise that I don't know where to
get the project's public keys from. According to [1], we should publish
a KEYS file on the web site somewhere, but as far as I know we don't.
Ian
[1] http://apache.org/dev/release-signing#public-key-not-found