I thought I’d share what it took to get secure boot working with a Gigabyte GA-H81-D3 motherboard and Gigabyte UEFI DualBIOS.
I just tried switching CSM support to “Always”, and my computer rebooted twice and then froze. So I’d say setting it to “Never” is needed. >_<
For reference:
https://doc.opensuse.org/documentation/leap/reference/html/book.opensuse.reference/cha.uefi.html
https://www.gigabyte.com/Motherboard/GA-H81-D3-rev-10/support#support-manual which ironically doesn’t mention the relevant Secure Boot options.
https://www.eightforums.com/threads/secure-boot-and-windows-8-activation.56219
Enabling secure-boot ought to imply CSM=never. But who knows – there are weird UEFI implementations out there.