Requirements

Verify the following requirements before you install the MCP Server for Vulnerability Remediation.

Deployment requirements

Table 1. Requirements
Requirement Details
Supported operating systems A supported 64-bit Windows Server environment on AMD64.
BigFix connectivity The MCP server host must reach the BigFix Server REST API over HTTPS, normally TCP port 52315.
BigFix authentication Each MCP client session requires a valid BigFix REST API bearer token.
Remediate entitlement The authenticated BigFix user must have the Remediate entitlement required by the vendor-defined policy embedded in the server binary.
MCP client connectivity MCP clients must reach the server's streamable HTTP listener, normally TCP port 9495.
MCP client capability A client that supports remote streamable HTTP MCP servers and custom request headers.
BigFix TLS trust A PEM-encoded CA certificate that validates the BigFix Server certificate and is readable by the MCP service account.
MCP listener trust The MCP client must trust the certificate presented by the MCP server. The client URL must match a certificate SAN.
Vendor connectivity Outbound HTTPS access to the vendor hosts required for the selected workflow, including Microsoft, Google, GitHub, NVD, and MSRC services.
Storage Space for the binary, configuration, generated TLS material, logs, and response data. Store exported Fixlets in an organization-approved content repository.
Service account An account with permission to run a Windows service and read/write the configured workspace.

Network summary

Table 2. Network summary
Source Destination Default port Purpose
MCP client MCP Server for Vulnerability Remediation 9495 Streamable HTTP MCP traffic, normally protected by TLS.
MCP Server for Vulnerability Remediation BigFix Server 52315 Bearer-token validation through the BigFix REST API.
MCP Server for Vulnerability Remediation Approved vendor services 443 CVE, patch, release, catalog, manifest, and download metadata.

Service account permissions

The Windows service account must be able to:

  • Read and execute the server binary.
  • Read config.yaml and the configured BigFix CA certificate.
  • Read the listener private key when custom TLS material is used.
  • Read and write the workspace and configured log locations.
  • Bind the configured listener port.
  • Establish outbound HTTPS connections to BigFix and supported vendor services.

A custom account must have the Log on as a service right. Grant it access to only the required installation, workspace, and log locations.