Installing the server
Use the Windows AMD64 release package to install the MCP Server for Vulnerability Remediation as a Windows service.
About this task
Keep the binary, configuration, CA certificate, logs, and any client-exported output under locations protected by operating-system permissions.
A release package contains:
- The
bes-mcp-fixlet-genexecutable, with an.exesuffix on Windows. - data/config.example.yaml.
- Supporting deployment documentation.
Create data/config.yaml from the example before you start the server. Do not place a BigFix token in this file.
Procedure
- Extract the Windows package into a protected installation directory, for example C:\Program Files\BES MCP Fixlet Generator.
- Copy data\config.example.yaml to data\config.yaml.
- Copy the organization-approved BigFix CA certificate into the data directory or another location readable by the service account.
- Edit data\config.yaml as described in Server configuration.
- Open an Administrator PowerShell session in the installation directory.
-
Install and start the Windows service.
.\bes-mcp-fixlet-gen.exe service install --workspace "C:\Program Files\BES MCP Fixlet Generator\data" .\bes-mcp-fixlet-gen.exe service start - Optional:
To run under a dedicated service account, install the service with the account
credentials.
.\bes-mcp-fixlet-gen.exe service install ` --workspace "C:\Program Files\BES MCP Fixlet Generator\data" ` --user "DOMAIN\service-user" ` --password "<password>" .\bes-mcp-fixlet-gen.exe service start
Results
The service runs from the configured installation and workspace paths.
What to do next
Confirm the binary identity:
bes-mcp-fixlet-gen version
Confirm that TCP port 9495 is listening and connect with a client
that trusts the listener certificate. A plain HTTP GET can return an
MCP protocol error; successful TLS connection without connection refusal is
sufficient for this transport check.