ARM systems designed for Windows 8 have the same requirement, and additionally must not allow users to disable it or install their own keys.
Prior to the launch, Microsoft said it was actually required that vendors allow Secure Boot to be disabled on x86.
Microsoft changed the spec in the wake of the controversy around UEFI secure boot. The current version of the spec (available from http://msdn.microsoft.com/en-us/library/windows/hardware/hh7...) does mandate the ability to use custom mode or disable UEFI secure boot, for non-ARM systems only.
There are also more hoops the Linux vendors have to jump that are explained in the article:
http://www.zdnet.com/linux-foundation-uefi-secure-boot-key-f...
Also, what I didn't understand myself - is the $99 Fedora has to pay for the key just something they have to pay once? Or do they have to pay $99 for every single machine? Because that would be pretty ridiculous if Microsoft managed to make Linux as expensive as Windows licenses, through UEFI.
But I think the $99 is cheaper and better (given what some idiot bios developers do - remember (IIRC) one link here on HN where the bios would look for 'Microsoft Windows' or 'Red Hat Linux' on boot entries?)