The security of the TLS protocol relies on clients authenticating the server. If a TLS client fails to authenticate the server, a network-based attacker can act as a man-in-the-middle and impersonate the server to the client.