Open-source project
asterisk/asterisk avatar
asterisk/asterisk

Asterisk: Building and Running the Open Source PBX from Source

The official Asterisk Project repository.

3,580 stars1,316 forksCNOASSERTION

At a glance

What is it?
Asterisk is C middleware between telephony channels and applications, built from source with configure, menuselect and make. It rewards operators who read the security document first, and punishes those who change the system clock.
Who is it for?
Adopt Asterisk if you need a telephony toolkit that spans SIP, PSTN and analog hardware and you are willing to build it from source and read the security document before exposing anything. Do not adopt it if you want a packaged appliance with a supported upgrade path you never touch.
Can I use it commercially?
Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
Is it still maintained?
Yes. The repository received new commits within the last day.
What is it written in?
Mainly C, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What Asterisk actually is, and who ends up running it

The README describes Asterisk as an Open Source PBX and telephony toolkit, and then gives the sentence that explains most of its design: it is middleware between Internet and telephony channels on the bottom, and Internet and telephony applications at the top. That framing matters more than the PBX label. A PBX is a product category with a feature list. Middleware is a position in a stack, and Asterisk occupies it for call control the way a web server occupies it for HTTP.

The audience follows from that. If you are wiring SIP endpoints to a carrier trunk, or bridging a SIP call into a traditional PSTN interface, Asterisk is the layer that does the translation. The README is explicit that it is not only Internet telephony: there is a large amount of support for traditional PSTN telephony, and supported hardware is listed as all analog and digital interface cards from Sangoma, any full duplex sound card supported by PortAudio, and the Xorcom Astribank channel bank. That hardware list is the real boundary of the project. If your deployment is pure SIP, you never touch it. If it is not, the hardware compatibility table decides whether Asterisk is even an option.

The stated platforms are GNU/Linux first, with the README saying it is developed and tested primarily there and supported on every major distribution. Mac OS X and the BSD variants are described as ports that reportedly run properly, a phrasing that tells you where the tested path is.

The build is the architecture: configure, menuselect, make

Asterisk does not ship as a single binary with everything compiled in. The build system is a module selector, and the repository layout reflects it: apps/, channels/, codecs/, bridges/, funcs/, res/, formats/, cdr/, cel/, pbx/, main/. Those directories are the categories you choose from at build time.

make menuselect is the step that makes this concrete. The README says it is needed if you want to select the modules that will be compiled and to check dependencies for various optional modules. So the dependency question is answered interactively, per module, rather than by a package manager. That is a deliberate trade-off: you get a build with no dead code and no libraries you did not ask for, and in exchange you own the dependency graph yourself. The README points at ./configure --help to see what libraries are being looked for, and names a few common ones as distribution packages: glibc-devel, ncurses-devel, openssl-devel, zlib-devel.

Configuration at runtime follows a single format across every file. Comments use a semicolon, not a hash, and the README gives the reason: # is a DTMF digit and may occur in many places. Files are divided into sections named in square brackets, with statements in the form variable = value, though older samples may use variable => value. One parser, many files, is a small decision that saves a lot of time when you are reading an unfamiliar config at three in the morning.

Installing Asterisk from source and reaching the CLI

The README's new installation path is a numbered sequence. Before any of it, it says to read the documentation on docs.asterisk.org, and it says the security information document must be read and understood before you attempt to configure and run an Asterisk server. Take that ordering literally.

Asterisk needs a C99-capable compiler or GCC 4.1 or higher, C library headers, and the headers and libraries for ncurses. The contrib/scripts/install_prereq script installs dependencies for most Debian and Redhat based distributions; the README notes it also handles SUSE, Arch, Gentoo, FreeBSD, NetBSD and OpenBSD but that those may have incomplete or out of date support.

First, generate the build configuration. If components are reported missing, run the prereq script and then rerun configure, because the script changes what configure can find:

bash
./configure
./contrib/scripts/install_prereq install
./configure

Next, choose modules. This is interactive, and it is where you decide which optional dependencies matter to you:

bash
make menuselect

Then compile and install. On a first installation the README suggests installing the sample PBX with demonstration extensions, and warns that make samples will overwrite any existing configuration files you have installed:

bash
make
make install
make samples

Finally, start in the foreground rather than as a daemon. The three v flags are the README's very very verbose mode, and the c gives you a console:

bash
asterisk -vvvc

You should see verbose initialization messages, and then a prompt that looks like *CLI>. From there, core show help lists commands, and core show help <command> documents a specific one. man asterisk covers starting, stopping and the command line options.

Two operational limits that decide whether your deployment holds

The README devotes separate sections to time and to file descriptors, and both are failure modes rather than tuning advice.

On time: Asterisk is sensitive to large jumps in time, and manually changing the system time with date(1) or similar may cause SIP registrations and other internal processes to fail. The instruction is to install and configure exactly one of ntpd/ntpsec, chronyd or systemd-timesyncd. Exactly one, not one or more. Running two time daemons against the same clock is how you get the jump the README is warning about, so a container image or a VM template that already ships one and then has another installed on top is a real hazard.

On file descriptors: in UNIX these cover network communication for SIP, IAX2 or H.323 calls and hardware access, not just files on disk. The README gives a concrete ratio: with a limit of 1024, a common default, Asterisk can handle approximately 150 SIP calls simultaneously. That number is the one to carry into capacity planning, because the default limit on many systems will cap you well below what the hardware can do. The README's remedy for PAM-based Linux is to edit /etc/security/limits.conf and add soft and hard nofile lines, with the example values shown as 4096.

Neither of these is a bug. They are the cost of a process that holds registrations and call state in memory and multiplexes many sockets, and they are the kind of thing you find out about in production if you skip the README.

Where Asterisk is the wrong tool, and what to use instead

Asterisk is the wrong tool when you want a managed service with a support contract and an upgrade path you do not own. The README's upgrade section is short and pointed: if you are updating from a previous version, read the Change Logs, with a link to the downloads directory. That is the whole upgrade story in the README. There is no rollback procedure documented there, no in-place migration tool, and no compatibility matrix. You are expected to read the changelog and understand what changed before you replace a working installation.

If that is not a responsibility you want, a hosted PBX or a vendor appliance is the honest alternative, and the difference is not features. It is who reads the changelog. With a hosted service, the provider absorbs the upgrade and you absorb the outage if they get it wrong. With Asterisk, you absorb both, and you get the ability to run the thing on your own hardware, bridge to analog and digital interfaces, and modify the source.

A second case where Asterisk is the wrong choice: a pure SIP deployment that only needs to register a handful of endpoints and route calls. The PSTN hardware support, the module selection and the configuration surface exist for deployments that need them. If you do not, you are carrying the complexity without using it. FreeSWITCH is the alternative usually named in this space, and the difference in approach is architectural: FreeSWITCH was designed around a central state machine with modules attached to it, while Asterisk's build system and directory layout show a channel-and-application model where modules are selected at compile time. Pick based on which model you can operate, not on a feature checklist.

Maintenance, licensing and what the repository tells you

The last push to the default branch was on 2026-09-23, and the repository is not archived. Recent releases on the release feed are 24.0.0-rc1, 23.6.0-rc1 and 22.12.0-rc1, all dated 2026-09-17. Three maintained branches with release candidates cut on the same day is the shape of a project that backports fixes rather than moving everyone forward at once. For an operator that means you choose a branch and stay on it, and you should expect the 22.x, 23.x and 24.x lines to diverge in what they receive.

Upgrade cost is therefore a function of which line you pick. The README does not document a supported skip, so the Change Logs are the only source for what changes between two versions, and the menuselect step means an upgrade can surface new module dependencies that did not exist in your previous build. Budget for a rebuild, not a binary swap.

On licensing: the top-level Makefile header states that the program is free software distributed under the terms of the GNU General Public License, and the repository carries both COPYING and LICENSE files. The repository metadata reports the license as NOASSERTION, which means the automated classifier did not resolve a single SPDX identifier. That is a discrepancy worth resolving with the COPYING and LICENSE files themselves, and with your own counsel, before you redistribute anything. The README also carries a copyright line naming Sangoma Technologies Corporation and other copyright holders, and the security document is linked separately from the license files.

Editorial conclusion

Adopt Asterisk if you need a telephony toolkit that spans SIP, PSTN and analog hardware and you are willing to build it from source and read the security document before exposing anything. Do not adopt it if you want a packaged appliance with a supported upgrade path you never touch. Verify three things first: that the Change Logs for your target release cover the jump you are making, that exactly one time synchronization daemon (ntpd, chronyd or systemd-timesyncd) is installed, and that your nofile limit is high enough for the call volume you expect.

Frequently asked questions

How do I install Asterisk on Ubuntu?

The README gives a source build rather than a package: run ./configure, install dependencies with ./contrib/scripts/install_prereq install if configure reports missing components, rerun ./configure, then make menuselect, make, make install and optionally make samples. The prereq script is described as covering most Debian and Redhat based distributions, which includes Ubuntu.

How do I install Asterisk on Ubuntu 22.04?

The README does not name specific distribution versions. It says Asterisk is developed and tested primarily on GNU/Linux and supported on every major distribution, and that the install_prereq script handles most Debian and Redhat based distributions, so the same configure, menuselect, make sequence applies.

How do I use Asterisk after it is running?

The README says to launch it in the foreground with asterisk -vvvc, which prints verbose initialization messages and then gives a console prompt of *CLI>. From there, core show help lists available commands and core show help <command> documents a specific one.

How do I install Asterisk at all?

You build it from source. The README requires a C99-capable compiler or GCC 4.1 or higher plus the C library headers and the ncurses headers and libraries, then runs ./configure, make menuselect, make, make install and optionally make samples.

Official sources

  1. asterisk/asterisk on GitHub
  2. Issues
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/asterisk-asterisk.svg)](https://hysenlabs.com/projects/asterisk-asterisk)