... is signing the request. ...
... and unless your bootloader appears in that list-- is signed by one of those signing keys, ...