Server configuration
Configure the listener, logging, and BigFix connection settings in config.yaml.
Example configuration
The following configuration uses the production BigFix REST API
port 52315:
mcp_server:
scheme: "https"
port: "9495"
read_only: false
disable_hitl: false
max_auth_failures: 5
lockout_duration_seconds: 300
max_response_bytes: 1048576
max_bulk_items: 100
tls:
dns_names:
- "mcp-fixlet-gen.example.com"
- "localhost"
ip_addresses:
- "127.0.0.1"
log:
file_path: "logs/server.log"
max_size_mb: 100
max_backups: 3
max_age_days: 28
compress: true
bigfix:
url: "https://bigfix.example.com:52315"
ca_cert_path: "bigfix-ca.pem"
auth_timeout_seconds: 30
Relative paths are resolved from the workspace supplied to service
install. The service fails to start if
bigfix.ca_cert_path is absent, unreadable, or does not contain
valid PEM certificate material.
Listener settings
| Setting | Description |
|---|---|
mcp_server.scheme |
Use https for deployed environments. Use
http only for isolated local testing. |
mcp_server.port |
MCP listener port. The documented default for this server is
9495. |
mcp_server.tls.dns_names |
DNS names included in an automatically generated listener certificate. |
mcp_server.tls.ip_addresses |
IP addresses included in an automatically generated listener certificate. |
mcp_server.tls.cert_path |
Optional custom listener certificate path. Configure together with
key_path. |
mcp_server.tls.key_path |
Optional private key matching cert_path. |
The hostname or IP in the MCP client URL must appear in the certificate Subject Alternative Name (SAN).
Runtime security settings
| Setting | Description |
|---|---|
mcp_server.max_auth_failures |
Consecutive authentication failures allowed before source-IP lockout. |
mcp_server.lockout_duration_seconds |
Duration of an authentication lockout. |
mcp_server.max_response_bytes |
Maximum accepted downstream response size. |
mcp_server.max_bulk_items |
Maximum accepted bulk item count. |
The current Fixlet Generator tools do not execute BigFix write
operations. The generic read_only and
disable_hitl settings remain part of the shared server runtime
but do not replace review of generated Fixlets.
BigFix settings
| Setting | Description |
|---|---|
bigfix.url |
BigFix Server REST API base URL, normally
https://<bigfix-server>:52315. |
bigfix.ca_cert_path |
PEM certificate or CA bundle used to validate the BigFix Server certificate. |
bigfix.auth_timeout_seconds |
Timeout for bearer-token authentication and entitlement validation requests. |
After bearer-token authentication succeeds, the server validates the user's Remediate entitlement using vendor-defined policy embedded in the signed binary. The entitlement policy is not customer-configurable.
Restarting after configuration changes
Restart the service whenever config.yaml, the listener TLS material, or the BigFix CA certificate changes.
.\bes-mcp-fixlet-gen.exe service restart