The computer's manufacturer loads it with a special certificate, so when the computer tries to boot, the bootloader has to include a signature signed with that initial certificate. This bootloader can in turn contain the next certificate to verify the operating system is signed correctly, the operating system in turn contains certificates that verify that user applications are signed correctly.
In theory this is a sound idea, in practice things and implementations are a lot more messy.