Firstly, we'd need a non-GPL bootloader. Grub 2 is released under the GPLv3, which explicitly requires that we provide the signing keys.
No, it says this:
“Installation Information” for a User Product means any methods, procedures, authorization keys, or other information required to install and execute modified versions of a covered work in that User Product from a modified version of its Corresponding Source
It would suffice to provide instructions that say, "install a signed version of grub, and use that to add your own keys to the whitelist".
If you are unable to use this captcha for any reason, please contact us by email at firstname.lastname@example.org