Actually, the OpenBSD people came up with "signify" which handles this more elegantly.
FTP is still advertised for download of this OS, but any tampering or otherwise corrupted files will not pass a signature test when signify is invoked.
The keys are rotated for every release, the next expected key is always included in the current OpenBSD release.
This system would be safe to fetch sensitive content over cleartext http.
EDIT: Here is a paper on signify: