The initial order was for the installation of a "pen-trap" to collect metadata on one account. According to the document, this is typically implemented by the provider without installing any FBI hardware.
"In this case, the SSL keys are 'information ... necessary to accomplish the installation and use of the [pen-trap]' because all other options for installing the pen-trap have failed. In a typical case, a provider is capable of implementing a pen-trap by using its own software or device, or by using a technical solution provided by the investigating agency; when such a solution is possible, a provider need not disclose its key."
The initial order was to provide metadata for all traffic involving a single account. It was only when Lavabit said they couldn't do this without disclosing their SSL private key that the FBI asked for the key.
From page 104 of http://s3.documentcloud.org/documents/801182/redacted-pleadi...:
"In this case, the SSL keys are 'information ... necessary to accomplish the installation and use of the [pen-trap]' because all other options for installing the pen-trap have failed. In a typical case, a provider is capable of implementing a pen-trap by using its own software or device, or by using a technical solution provided by the investigating agency; when such a solution is possible, a provider need not disclose its key."