RPMs are signed packages.
The usual way of using them is configuring repository to your system and using rpm/dnf/yum to install the package which will add the signing key to your system and validate the package when downloaded.
If you REALLY want to do this semi manually.