[p2-dev] Documentation about pgp signing of Eclipse plugins


in context of expired spotbugs certificate (see 

I'm looking for pointers (wiki/blog/help page) about how one can "sign" Eclipse bundles with pgp? 

Google finds few bugs but no explanation to following questions :

- prerequisites (which Eclipse version supports that)
- build requirements (which tooling needed, on which platform etc)
- instructions for signing itself (command line etc)
- which side effects ot has on compatibility with old Eclipse platforms (can pgp signed bundle be installed on older Eclipse that doesn't know anything about pgp)

These below seem to be related but don't give answers to questions above:

Is there any official documentation available ?
Kind regards,
Andrey Loskutov
Спасение утопающих - дело рук самих утопающих

