The computer's manufacturer loads it with a special certificate, so when the computer tries to boot, the bootloader has to include a signature signed with that initial certificate. This bootloader can in turn contain the next certificate to verify the operating system is signed correctly, the operating system in turn contains certificates that verify that user applications are signed correctly.
In theory this is a sound idea, in practice things and implementations are a lot more messy.
Case in point: TPM is not required to implement UEFI Secure Boot. You can test yourself in a QEMU VM, if you don’t believe me.
From my understanding, TPM is just a separate crypto-module meant to keep the keys secret even from the CPU and OS itself, allowing you to do various crypto and security related things with higher confidence of the keys not getting leaked.
Applications includes passwordless disk-encryption (MS BitLocker) but also hard-to-crack DRM, making the TPM a somewhat controversial piece if hardware.
Someone please correct me if I’m wrong or my answer is inaccurate in any way ;)
Secure Boot is implemented by UEFI, so it can block the loading of a particular bootloader. You can have Secure Boot without a TPM or have a TPM without Secure Boot. They can be useful together though as you can have a disk-encryption key with a policy saying "I can only decrypt stuff if you've booted using Secure Boot in a particular configuration".
As for DRM, the TPM doesn't work very well as part of a DRM solution (as it's entirely passive). This is probably why very few (if any) DRM products use TPM. Most PC DRM that I've heard of either uses Windows Kernel modules or Intel SGX.
I believe you, but doesn't that mean that there is nothing particular secure about this operation ?
But thank you for the correction, I was under the impression that secure boot neccessarily needs a TPM to store it's keys.
Not at all. The trusted signing-certificates don’t need to be stored securely since they only contain public keys.
This is typically stored in NVRAM or EFI-variables.