I got a message along the lines about accepting the signing of so-and-so during first install-medium boot (DVD) by selecting ‘yes’;), but my first fresh boot I didn’t get signed-shim’s “Shim UEFI key management” options screen…so do I need to reboot again for ‘2nd boot post-install’?::sick: Also, a hint that might help you determine answer to my question…/etc/uefi/certs/ directory exists with a ########.crt.
It’s normal to not get any special indication.
Try the command:
bootctl status
You can run that as an ordinary user. It should tell you whether secure-boot is enabled and give some information about how you booted.
That’s a one-time only message. You won’t get it again unless opensuse changes/updates their key.
The key management stuff only comes into play if you create your own key (machine owner key).