We check the md5 bit of the header now and do regrabs if it's at a point that we can. Checking the GPG sig introduces a difficult chicken and the egg problem of where to get the key (especially for cases where people customize their install trees). See https://bugzilla.redhat.com/bugzilla/998