It looks like the second GIGABYTE certificate is technically invalid according to the Secure Boot specs. Its serial number is negative and it has an RSA-4096 key which is too big.
I’ve added some logic to handle this that should allow your system to work – thanks for sending me the db certificates from your system.