gnupg-1.4.2.tar.bz2.sig was signed with key 0x57548DCD but gnupg-1.4.2.1.tar.bz2.sig is signed with 0x1CE0C630, which is not in turned signed with the old key. Why? How do we verify it's trustworthy? Thanks!