validating a pkg's signature before installation?