.. but the warning about signing seemed unusual enough to question.
http://debian-knoppix.alioth.debian.org/ isn't part of the Debian releases and maintainer of most of the packages within the archive there is "Klaus Knopper <[email protected]".

You can provide archive signatures in an archive under your maintenance, but it isn't stipulated. Prof. Knopper signs the whole ISOs with his key, not his archive. If in doubt you can download a package of his archive, build his checksum and compare this with the checksum listed in
http://debian-knoppix.alioth.debian.org/Sources.gz