Even then, you should also verify it out-of-band (e.g. compare full fingerprints over OTR with someone you trust who has previously saved the same .asc file)
Agreed, depending on how paranoid you are. The server serving the .asc file over SSL could still be compromised (among other things). Similarly you are unable ascertain that recipient's private key isn't compromised either, or recipient is forced to decrypt, et cetera.