AMD's Secure Memory Encryption (SME) feature will remain disabled by default in future Ryzen-based Linux PCs. That's because the feature has been found to be very problematic on some of those systems.
A decade ago, AMD added a protection to its high-end CPUs to protect them against cold boot attacks and other types of physical exploits that siphon sensitive data out of the connected memory chips.
Most people will never need to think about Secure Boot certificates. They live deep in your PC’s firmware, do their job silently, and have been doing so since 2011 without asking for much in return.