Requirements
Verify the following requirements before you install the MCP Server for Vulnerability Remediation.
Deployment requirements
| Requirement | Details |
|---|---|
| Supported operating systems | A supported 64-bit Windows Server environment on AMD64. |
| BigFix connectivity | The MCP server host must reach the BigFix Server REST API over HTTPS, normally TCP port
52315. |
| BigFix authentication | Each MCP client session requires a valid BigFix REST API bearer token. |
| Remediate entitlement | The authenticated BigFix user must have the Remediate entitlement required by the vendor-defined policy embedded in the server binary. |
| MCP client connectivity | MCP clients must reach the server's streamable HTTP listener,
normally TCP port 9495. |
| MCP client capability | A client that supports remote streamable HTTP MCP servers and custom request headers. |
| BigFix TLS trust | A PEM-encoded CA certificate that validates the BigFix Server certificate and is readable by the MCP service account. |
| MCP listener trust | The MCP client must trust the certificate presented by the MCP server. The client URL must match a certificate SAN. |
| Vendor connectivity | Outbound HTTPS access to the vendor hosts required for the selected workflow, including Microsoft, Google, GitHub, NVD, and MSRC services. |
| Storage | Space for the binary, configuration, generated TLS material, logs, and response data. Store exported Fixlets in an organization-approved content repository. |
| Service account | An account with permission to run a Windows service and read/write the configured workspace. |
Network summary
| Source | Destination | Default port | Purpose |
|---|---|---|---|
| MCP client | MCP Server for Vulnerability Remediation | 9495 |
Streamable HTTP MCP traffic, normally protected by TLS. |
| MCP Server for Vulnerability Remediation | BigFix Server | 52315 |
Bearer-token validation through the BigFix REST API. |
| MCP Server for Vulnerability Remediation | Approved vendor services | 443 |
CVE, patch, release, catalog, manifest, and download metadata. |
Service account permissions
The Windows service account must be able to:
- Read and execute the server binary.
- Read config.yaml and the configured BigFix CA certificate.
- Read the listener private key when custom TLS material is used.
- Read and write the workspace and configured log locations.
- Bind the configured listener port.
- Establish outbound HTTPS connections to BigFix and supported vendor services.
A custom account must have the Log on as a service right. Grant it access to only the required installation, workspace, and log locations.