Apt proxy repo: GPG failure

Hello,

I use NRM for internal hosts behind a firewall to receive upstream packages without burdening the network - brilliant tool!

For Canonical repos, I find no issues.

But for 3rd party repos, like Microsoft, Puppet and Docker.io - they all complain about GPG keys.
Certainly because the hosts use these repos without downloading the 3rd party keys.

I have configured my hosts to refer to the NRM proxied (3rd party only) repos with ‘[trusted=yes]’ to bypass this. I know this to be bad practice.

For machines behind a firewall like this, can NRM do anything to proxy the GPG keys my hosts need?
Does anyone care to share how they might do this?

Thanks v much.