Sign repository indexes
Once #755 is done, we'll want to sign the index files.
From our [planning document](https://docs.google.com/document/d/12CvqlRa_vBjjaQItizwsHww-6HXx9-QPU2cpqxnfjvs):
MUST: Sign indexes for a repository
- Deal with having more keys than fit in our HSM
- New task to sign Release files (produce both Release.gpg and InRelease in one go)
- Task to generate a key for a repository
- Decide on granularity
- Design how keys are stored and linked to repositories
- Permissions for key usage
issue