package_to_container: create a signed app

In addition to updating package_to_container and the generated
config.json files (includes changes from CL:417097), output the
manifest and sign it.

The layout is:
  manifest.json - file w/config.json & rootfs hashes
  manifest.json.sig - signature of manifest.json

By default we use the devkey from vboot.

TEST=run_oci only runs containers with a valid manifest.json{,.sig}

