add checksum-maven-plugin

http://www.apache.org/dev/release-distribution#sigs-and-sums
> New policy :
>
>   -- SHOULD supply a SHA-256 and/or SHA-512 checksum file
>   -- SHOULD NOT supply MD5 or SHA-1 checksum files

See also: WW-4951
1 file changed