... your bootloader for a signed hash of itself and verify that the signature of the hash ...
... and unless your bootloader appears in that list-- is signed by one of those signing keys, ...