Server configuration

Configure the listener, logging, and BigFix connection settings in config.yaml.

Example configuration

The following configuration uses the production BigFix REST API port 52315:

mcp_server:
  scheme: "https"
  port: "9495"
  read_only: false
  disable_hitl: false
  max_auth_failures: 5
  lockout_duration_seconds: 300
  max_response_bytes: 1048576
  max_bulk_items: 100
  tls:
    dns_names:
      - "mcp-fixlet-gen.example.com"
      - "localhost"
    ip_addresses:
      - "127.0.0.1"
log:
  file_path: "logs/server.log"
  max_size_mb: 100
  max_backups: 3
  max_age_days: 28
  compress: true
bigfix:
  url: "https://bigfix.example.com:52315"
  ca_cert_path: "bigfix-ca.pem"
  auth_timeout_seconds: 30

Relative paths are resolved from the workspace supplied to service install. The service fails to start if bigfix.ca_cert_path is absent, unreadable, or does not contain valid PEM certificate material.

Listener settings

Table 1. Listener settings
Setting Description
mcp_server.scheme Use https for deployed environments. Use http only for isolated local testing.
mcp_server.port MCP listener port. The documented default for this server is 9495.
mcp_server.tls.dns_names DNS names included in an automatically generated listener certificate.
mcp_server.tls.ip_addresses IP addresses included in an automatically generated listener certificate.
mcp_server.tls.cert_path Optional custom listener certificate path. Configure together with key_path.
mcp_server.tls.key_path Optional private key matching cert_path.

The hostname or IP in the MCP client URL must appear in the certificate Subject Alternative Name (SAN).

Runtime security settings

Table 2. Runtime security settings
Setting Description
mcp_server.max_auth_failures Consecutive authentication failures allowed before source-IP lockout.
mcp_server.lockout_duration_seconds Duration of an authentication lockout.
mcp_server.max_response_bytes Maximum accepted downstream response size.
mcp_server.max_bulk_items Maximum accepted bulk item count.

The current Fixlet Generator tools do not execute BigFix write operations. The generic read_only and disable_hitl settings remain part of the shared server runtime but do not replace review of generated Fixlets.

BigFix settings

Table 3. BigFix settings
Setting Description
bigfix.url BigFix Server REST API base URL, normally https://<bigfix-server>:52315.
bigfix.ca_cert_path PEM certificate or CA bundle used to validate the BigFix Server certificate.
bigfix.auth_timeout_seconds Timeout for bearer-token authentication and entitlement validation requests.

After bearer-token authentication succeeds, the server validates the user's Remediate entitlement using vendor-defined policy embedded in the signed binary. The entitlement policy is not customer-configurable.

Restarting after configuration changes

Restart the service whenever config.yaml, the listener TLS material, or the BigFix CA certificate changes.

.\bes-mcp-fixlet-gen.exe service restart