Description of issue or feature request:
A verification of signed metadata by a threshold of keys is needed both for client and repository.
Metadata already has vanilla one-signature verify and could potentially be the right location for this implementation. See #1060 (comment) for thoughts about that distinction.