Production signing should use a remote signer so private keys never enter the ordinary web process. TSA failures must be recorded, never silently faked.
Learn
How C2PA signatures work
The Claim signature proves a private-key holder issued this claim. Asset binding proves the claim still matches the bytes you are looking at. You need both.