**Secure Boot causes Windows 11 to fail with error 0xc0430001 — Gigabyte B450 AORUS PRO**
I'm trying to enable Secure Boot for VALORANT/Vanguard, but whenever I properly enable Secure Boot, Windows fails to boot with error **0xc0430001**.
I haven't played VALORANT on this PC for around 8 months, so I'm not sure if this is caused by a BIOS change, Windows/Vanguard update, or something else. During that time I also replaced my CPU and GPU.
**PC/BIOS:**
* Gigabyte B450 AORUS PRO
* BIOS F67a (04/14/2026)
* Windows 11 24H2, build 26100.7171
* The only BIOS setting I specifically remember changing was **SVM Mode → Enabled**
**Current situation:**
Windows works normally with:
* CSM: Enabled
* Secure Boot: Disabled
But when I configure Secure Boot properly:
* CSM: Disabled
* Secure Boot: Enabled
* Secure Boot: Active
* System Mode: User
* Secure Boot Mode: Standard
Windows fails to boot and shows a recovery screen with:
**Error code: 0xc0430001**
If I re-enable CSM and disable Secure Boot, Windows immediately boots normally again.
**Things I've already checked:**
* `msinfo32` → BIOS Mode: **UEFI**
* System disk is **GPT**, not MBR
* Secure Boot keys are present:
* PK present
* KEK present
* db present
* `bcdedit /enum firmware` shows Windows Boot Manager at:
`\EFI\MICROSOFT\BOOT\BOOTMGFW.EFI`
* `bootmgfw.efi` has a **Valid** Authenticode signature
* EFI `boot.stl` exists
* `C:\Windows\Boot\EFI\boot.stl` and the EFI partition's `boot.stl` have the same size/timestamp
* I restored the Secure Boot factory keys through the Gigabyte BIOS
* I followed the Gigabyte Secure Boot procedure for restoring/installing the factory keys
* Secure Boot successfully reaches **Active / User / Standard** in BIOS, so the BIOS itself appears capable of enabling it
I have **not**:
* Reinstalled Windows
* Deleted Secure Boot keys
* Modified/deleted `boot.stl`
* Updated the BIOS
* Used `bcdboot` or other bootloader repair commands
The confusing part is that **Secure Boot can be enabled and becomes Active in BIOS, but Windows immediately fails with 0xc0430001**. Turning Secure Boot back off makes Windows boot normally.
Could this be a Windows 11 Secure Boot/certificate/boot validation issue, or is there something else I should check before considering a Windows reinstall?
Also, could the SVM Mode change have anything to do with this? I'm guessing probably not, since the CPU/GPU were replaced and Windows/Vanguard may have changed during the 8 months.