It doesn't say that at all, the FSF is explicitly saying they are fine with the GPLv3 on systems with boot-time signature checking, as long as modified software is loadable by the end user. In the specific case where a vendor distributes a boot locked system with GPLv3 GRUB then it's the vendor's responsibility to comply with the license, not by distributing a private key but by fixing the firmware to allow key management/disablement.