When I start my ASUS ROG FX553V running Windows 11, I get a "Secure Boot Violation — Invalid Signature Detected" message. Windows starts normally if I disable Secure Boot in the firmware settings, but I'm unsure what caused the problem or whether it's safe to keep using the laptop that way. I haven't installed Linux or Battlefield 6, which were mentioned as possible causes in my searches. How can I troubleshoot the issue and restore Secure Boot safely?
4 Answers
You may need to refresh the Secure Boot keys in the firmware rather than simply toggling Secure Boot. Follow a reputable Microsoft support guide for restoring or updating the default Secure Boot keys, and be careful not to change disk or boot-mode settings without a backup. Tools such as Mosby may help on systems where the firmware keys are outdated, but verify compatibility and understand the recovery steps first.
This can happen when an older BIOS no longer recognizes a boot certificate that has expired or been replaced. First install every available Windows update, then check ASUS’s support page for the newest BIOS or firmware for your exact FX553V model. After updating, try enabling Secure Boot again. Since this is an older laptop, there may not be a newer BIOS available, but it’s still worth checking.
Secure Boot verifies that the software loaded before Windows has a trusted digital signature. The warning can come from an outdated certificate, a damaged boot configuration, unsupported boot files, or malware. While troubleshooting, run a Windows Defender Offline scan, since it checks the system before normal Windows startup.
Disabling Secure Boot will usually let Windows run, but it removes one layer of protection against boot-level malware and tampering. It’s generally better as a temporary workaround while you investigate. Back up important files, avoid changing BIOS or partition settings casually, and restore Secure Boot once the certificates, keys, or boot files have been corrected.

I don’t see any newer Windows or BIOS updates available. The laptop is fairly old, and its last BIOS release was in 2019. How can I tell whether the Secure Boot certificate or keys are expired?