If we just adopt a policy of digitally signing themes, then there is no need to
have a "safe theme" file on each machine. A user would download a theme, the
signature would be checked and if it was verified, the theme would install.

If the signature could not be checked because the user did not have the right
public key, they could download it from somewhere. This is exactly the same as
with PGP/GPG encrypted email -- if somebody does not have my public key they can
go to a key repository like and download it. RedHat uses similar
things for their rpms. 


