1) Not all signatures are on chain. All that is needed is to post the signature somewhere and verify it with the message and public key.
2) Whoever has the private key can produce the signature, and the signature can only be produced by someone who has the private key (assuming the cryptography is secure)