What? transactions? We're talking about an embedded system here, recording unnecessary information because of the odd chance that a user wants to roll back to an old, possibly even more faulty version of something is a good idea?
I don't know what you mean about the embedded gpg signing, can't .deb files be signed?
To sign a package during it's been built, simply add '--sign': rpmbuild -ba --sign
And don't even get me going about the LSB, their idea of standards is everyone doing the same misguided stuff they do.
The Linux Standard Base was created to lower the overall costs of supporting the Linux platform. By reducing the differences between individual Linux distributions, the LSB greatly reduces the costs involved with porting applications to different distributions, as well as lowers the cost and effort involved in after-market support of those applications.