Surely the answer is to sign distributions (or not) as verified as originating from a domain (eg microsoft.com), then let the user choose which os to boot in the bios (or whatever becomes). Then if you want to run an os from an untrusted domain you can, or you can just stick to whatever is sighed as coming from microsoft
As far as I can see all pc manufacturers would need to do is verify the certificate of each os on an os selection screen and display the result to the user
As far as I can see all pc manufacturers would need to do is verify the certificate of each os on an os selection screen and display the result to the user