I confirmed that they have not changed their repo signing key, as I have a
backup copy of it and I checked it against the current one. Could it be that
they signed `susedata.xml.gz` with the wrong key? I don't really understand PGP
all that well...  But the repo contents are indeed still downloadable if you
know the exact path/name. For example:
The problem is that Zypper won't accept it and it throws those scary errors.

This started late last week, I believe on Friday. It feels like they made a
late Friday mistake and then took the weekend off and haven't noticed the
problem yet.

