Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Applies to: ✔️ Linux VMs
Summary
The Azure VM Instance Metadata Service (IMDS) Verification Tool for Linux is a bash script that diagnoses certificate chain, connectivity, and certificate store problems related to IMDS on Linux VMs. The tool automatically detects your Linux distribution and provides distro-specific fix commands.
How the tool works
The tool runs seven diagnostic phases:
| Phase | Check | What it does |
|---|---|---|
| 1 | IMDS Reachability | Tests connectivity to 169.254.169.254 |
| 2 | Attestation Fetch | Retrieves the attested document and extracts the signing certificate from the PKCS#7 envelope |
| 3 | Chain Validation | Validates the certificate chain against the system trust store by using openssl verify |
| 4 | OCSP Detection | Automatically detects which OCSP intermediate (02-16) your VM is using |
| 5 | Store Inventory | Checks for DigiCert Root G2, Microsoft TLS RSA Root G2, and the OCSP intermediate in the trust store |
| 6 | Connectivity | Tests TCP connectivity to AIA, CRL, and OCSP endpoints |
| 7 | Summary | Detects your distribution and provides the correct fix commands |
| 8 | AutoFix (optional) | When you specify --autofix: downloads missing certificates, installs them, updates the trust store, and re-validates the chain |
Supported distributions
| Distribution | Cert Path | Update Command |
|---|---|---|
| Ubuntu / Debian | /usr/local/share/ca-certificates/ |
update-ca-certificates |
| RHEL / CentOS / Oracle Linux / Azure Linux | /etc/pki/ca-trust/source/anchors/ |
update-ca-trust |
| SUSE / openSUSE | /usr/share/pki/trust/anchors/ |
update-ca-certificates |
How to run the tool
az vm run-command invoke \
--resource-group <resource-group> \
--name <vm-name> \
--command-id RunShellScript \
--scripts @Linux_IMDSValidation.sh
DER to PEM conversion
Important
Microsoft provides certificates in DER format. Linux trust stores require PEM format. The tool's fix commands include the conversion step. If you install certificates manually, always convert first:
openssl x509 -in certificate.der -inform DER -out certificate.crt