Ideally, it goes something like this --
1. Start with the master keys. Download them from their website & import them into your keyring.
2. Fetch signatures for those keys from some key servers. (E.g. gpg --recv-keys 6A93B34E).
3. Examine the signatures (E.g. gpg --list-sigs 6A93B34E). Do you trust anybody in that list to have verified the ownership of the keys?
If "yes", then import the release keys and verify that _they_ have been signed by the master keys. You can use the release keys to verify the downloaded binary.
If "no", then you might recurse down those keys to see if you know anyone who signed any of _them_. At this point, you'll need to consider very carefully what your trust policy is going to be.