Just in case that it helps somebody:
I had two machines running 1.20. Thus I downloaded version 1.4 (ilo5_140.fwpkg) and got the "invalid signature"-message as well.
Turns out, this file needs to be unzipped and the bin-file inside is the one to go with.