When you install openSUSE-signkey-cert package and reboot, GRUB will ask you whether to enroll the new cert key or not. If you proceed this properly (not only pressing ENTER), the key will be enrolled to the MOK list, and the kernel will verify the signature with this new cert. Note that the MOK enrollment happens only once after this package installation. You can retry either manually via mokutil invocation, or just uninstall and re-install openSUSE-signkey-cert package, and reboot/enroll at GRUB.