Implement check of PGP signatures using the system's pacman keyring

When synchronizing Arch Linux promoted releases we want to verify that detached PGP signatures belong to trusted key IDs from the system's pacman keyring.