http://openvz.org/Package_signatures
All the packages that are released by OpenVZ project are digitally signed by OpenVZ GPG key. Thus, you can check that those packages are indeed came from OpenVZ.
1 Public and private keys
1.1 OpenVZ public key
2 Checking RPM packages
3 Checking files
3.1 Importing the public key
3.1.1 From a local file
3.1.2 From the default keyserver
3.1.3 From the pgp.mit.edu keyserver
3.2 Checking the signature