GRUB to skip kernel signature check

Hello OpenSUSE experts!

To use my custom kernel I want GRUB2 to skip kernel signature check.

How can I do that?

I use Shim to boot UEFI-based system (secure boot enabled).
Shim runs GRUB2, and GRUB2 wants my kernel to be signed.
I want to avoid signature check.
OpenSUSE Leap 42.1 64-bit, Asus T200TA, 64-bit UEFI.
GRUB2 2.02~beta2

#cat grubenv

Thank you!

Turn off secure boot.

There are two choices:

(1) Disable secure-boot in your UEFI firmware;
(2) Sign the kernel yourself. That’s what MokManager is all about.

Thank you!