... and unless your bootloader appears in that list-- is signed by one of those signing keys, ...
... evident. If you try to extract the keys from a TPM, it's supposed to be really obvious ...