All plugins must be GPG signed by a certificate which is known to the pljugin installer subsystems.
Plugin certificates are stored on a per plugin basis in a file called %{idp.home}/credentials/pluginid/truststore.asc.
This is a efore installing a plugin you SHOULD