... comes from a trusted party, someone you trust. Once you trust the bootloader to faithfully ...
... and unless your bootloader appears in that list-- is signed by one of those signing keys, ...