diff --git a/docs/reference/client-config.md b/docs/reference/client-config.md index 1395fea164..919cafa0f2 100644 --- a/docs/reference/client-config.md +++ b/docs/reference/client-config.md @@ -132,7 +132,9 @@ but the pinned certificates will take highest priority for validation, followed by the pinned CA, followed by TOFUS (TOFU over HTTPS). The diagram below describes this validation flow: -
Trust pinning flow
+
+![Trust pinning flow](../images/trust-pinning-flow.png) +
Only one trust pinning option will be used to validate a GUN even if multiple sections are specified, and any validation failure will result in a failed