Secure Boot checks software signatures at startup. SteamOS disables it by default because its components aren't signed. If you enable Secure Boot by enrolling your own keys, SteamOS won't boot. Disabling it afterward is near impossible, effectively locking out any unsigned OS