I believe for OpenSUSE it uses MokManager to get the user to trust the OpenSUSE CA. But it's been a while since I tried it so I might be misremembering. (MokManager is broken on my mobo so I switched to systemd-boot + my own signing keys, which is better for security anyway.)