Is your feature request related to a problem? Please describe. It's becoming increasingly difficult to automate verification of the releases. For "gpg --verify SHA256SUMS.asc SHA256SUMS" to succeed, all the keys have to be imported. Some keys are not present on public keyservers and keyservers are anyway commonly considered as unreliable. Currently for v23, after importing 27 (!) keys (others are not available) the SHA256SUMS.asc verification still fails.
Describe the solution you'd like Reduce the signer list to a set of well known, trusted signers and have their keys optionally signed by whoever verified their identity and is willing to sign. Alternatively, provide one signature file PER signer, not a global file that always fails to pass all checks.