It's not "digitally signed by Microsoft", but you need to obtain the needed keys, or have them in the UEFI databases. See and

Microsoft is strongly pushing to have its keys installed on every machine, and to have SecureBoot active by default, and on some systems, without the option of being disabled. But if you look at the Linux Foundation paper, you will surprisingly find they not object with this, as long as it is a customer choice (and it's not really different from what Apple does to secure its devices...)

