James Pifer wrote:
By signing those packages with your gpg key and importing the key into RPM or turning off the gpg key check if you are sure that you can trust those packages in avoiding middle men attacks.When you have your local mirror created how do you deal with gpg keys?
Fedora Bug Triaging - http://fedoraproject.org/wiki/BugZappers