diff --git a/documentation/ref-manual/variables.rst b/documentation/ref-manual/variables.rst
index b432488a012..645bb1453d1 100644
--- a/documentation/ref-manual/variables.rst
+++ b/documentation/ref-manual/variables.rst
@@ -3173,7 +3173,18 @@ system and gives an overview of their function and contents.
       intending to verify signatures in another context than booting via
       U-Boot.
 
-      This variable is set to "0" by default.
+      If :term:`UBOOT_SIGN_ENABLE` is set to “1” and :term:`FIT_SIGN_INDIVIDUAL`
+      is left at its default value of “0”, only the configurations are signed.
+      However, the configuration signatures include the hashes of the referenced
+      image nodes. This means that the entire FIT image is appropriately signed.
+
+      If :term:`UBOOT_SIGN_ENABLE` is set to “1” and :term:`FIT_SIGN_INDIVIDUAL`
+      is set to “1”, then the FIT image is signed twice, which is redundant.
+      As this leads to additional complexity without providing any obvious
+      advantage, this feature will likely be removed in a future version.
+
+      Signing only the image nodes is intentionally not implemented by OE-core,
+      as it is vulnerable to mix-and-match attacks.
 
    :term:`FIT_SIGN_NUMBITS`
       Size of the private key used in the FIT image, in number of bits.
