binman: doc: Add documentation for fdt_add_pubkey bintool

Add documentation for btool which calls 'fdt_add_pubkey'

Signed-off-by: Lukas Funke <lukas.funke@weidmueller.com>
Reviewed-by: Simon Glass <sjg@chromium.org>
diff --git a/tools/binman/bintools.rst b/tools/binman/bintools.rst
index dd2a22b..9d8f161 100644
--- a/tools/binman/bintools.rst
+++ b/tools/binman/bintools.rst
@@ -194,3 +194,13 @@
 
 
 
+Bintool: fdt_add_pubkey: Add public key to device tree
+------------------------------------------------------
+
+This bintool supports running `fdt_add_pubkey` in order to add a public
+key coming from a certificate to a device-tree.
+
+Normally signing is done using `mkimage` in context of `binman sign`. However,
+in this process the public key is not added to the stage before u-boot proper.
+Using `fdt_add_pubkey` the key can be injected to the SPL independent of
+`mkimage`