Today I:
- made a testid user
- enrolled testid user (using keychain)
- forgot testid user
- reset testid enrollment
- downloaded testid.jwt
- tried to add testid.jwt back to ZDEW and got the "Key Generation Failed" error

It appears that if you forget an identity and try to reenroll the exact same name you will get this error. If you rename the identity in ziti, it appears to happen as well. I renamed to testid2, reset enrollment, downloaded the .jwt and it happened