in reply to @ 2016-51 04:11 UTCI said this in my other comment, but to be very clear: the only good way to do this is with a third-party signing server, which could be libre or not (obviously we hope that it is). You want third party verification, so you need a third party.