When SIP phones registering to a MX-ONE PBX, you can link each phone's unique MAC address to a specific extension number. The phone then attempts to download its configuration file from an IP Phone Configuration Server (e.g., HTTP or HTTPS server).
This application automatically generate configurations for both MX-ONE and the phones contains the following:
- Extension number for the phone
- Common Service Profile number
- LIM number
- Extension's first and second names
- Authentication code
- SIP server IP address
You can use the python script gen_ext_conf.py in a command line interface (CLI) or run a modern Web UI application. The Web UI developed via AI (LLM) code generation, built entirely under my direct control and architectural oversight.
This project provides a web-based interface built with the Streamlit Python framework.
Install dependencies:
pip install -r requirements.txtStart the application by running run.bat or:
streamlit run app.pyOnce started, open your web browser and navigate to: http://localhost:8501/
Use the Browse files button to select and upload a CSV file.
The script automatically detects "," or ";" CSV file delimiter.
After uploading, the application displays a preview of the CSV file contents for verification.
Check the imported rows to ensure the data has been parsed correctly.
The lines with detected errors will be ignored. If the imported result is acceptable, you can process the file, otherwise edit and upload new CSV file again.
Process the imported rows and download the generated configuration files as a single ZIP archive.
Encrypt the generated configuration files and download the encrypted output as a ZIP archive.
The gen_ext_conf.py script automates the generation of configuration files for each phone. It creates a unique authentication code for each phone per each MAC address. The process relies on a pre-prepared file with default name test_mac.csv, which contains a list of MAC addresses, their corresponding extension numbers, Common Service Profile (CSP) numbers, LIM numbers and names.
Depending from MAC address vendor, the script generates different MAC configs for Mitel and Fanvil SIP-phones.
In addition to generating configuration files, the gen_ext_conf.py script also generates a set of MX-ONE shell commands. These commands, saved in the extensions.sh file, are used in the PBX CLI to set authentication codes for each extension. When using the MD5a1 format for authentication codes, the passwords are securely hashed and are not visible in plain text. However, the clear-text passwords are saved in the auth.txt output file.
MAC,EXTENTION,CSP,LIM,Name1,Name2
#MAC,EXT,CSP,LIM,First name, Second name # - Exactly 6 fields
14:00:E9:11:11:11,1111,0,1,First Name,Second name
14:00:E9:22:22:22,2222,2,1,F.,SEC
14:00:E9:33:33:33,3333,3,1,First only,
14:00:E9:44:44:44,4444,4,2,First name verylonglonglong, Second veryverylongnamename
14:00:E9:55:55:55,5555,5,2,,Only second
14:00:E9:66:66:66,6666,6,2,, # both names empty
# Wrong rows
14:00:E9:66:66:67,6667,0,1,,Wrong,line # 7 fields
14:00:E9:66:66:68,6668,01, # only 4 fields
14:00:E9:66:66:77,6677,,1,, # no csp
# MAC
0C:38:3E:77:77:77,7777,1,2,Fanvil,
11:11:11:11:11:11,1100,1,1,Wrong,MAC
Note: The Name1 and Name2 fields are limited to 20 characters in MX-ONE and will be truncated by the script to avoid command execution errors.
The script allows you to configure the input CSV file separator, choose the desired password length and SIP proxy IP address.
COLS = 6
DELIM = "," # CSV file separator
DIGITS = 14 # length of auth code
MAC_MITEL = "1400E9"
MAC_FANVIL = "0C383E"
SIP_PROXY = { # LIM: IP
"1": "192.168.1.11",
"2": "192.168.2.11",
"3": "192.168.3.11",
"4": "192.168.4.11"
}
BACKUP_1 = True # Add LIM1 as a backup SIP proxy/registrarIf the constant TEST is set to True in the gen_ext_conf.py script, the output will be generated in the _test folder, otherwise will be created a folder with a date as a name in YYYYMMDD format.
Run the script gen_ext_conf.py <mac.csv>:
$ python ./gen_ext_conf.py
Using default 'test_mac.csv' file for input
20260203-204734
Generated 9 config files
Warnings (3):
- Line 5: name1 trimmed to 20 characters
- Line 5: name2 trimmed to 20 characters
- Line 7: Both name1 and name2 are empty
Completed with 4 errors:
- Line 9: Expected 6 fields, got 7 → 14:00:E9:66:66:67,6667,0,1,,Wrong,line
- Line 10: Expected 6 fields, got 4 → 14:00:E9:66:66:68,6668,01,
- Line 11: Missing required field (mac/ext/csp/lim) → 14:00:E9:66:66:77,6677,,1,,
- Line 14: Unknown MAC (111111)
Test exit!
<MAC>.cfgfiles- file with passwords:
auth-<date-time>.txt - file with commands:
extensions-<date-time>.sh(Unix LF) <MAC>.tuzencrypted files (generated in a local folder)
sip line1 user name:4444
sip line1 auth name:4444
sip line1 password:vHgddJkbEfIcpn
sip proxy ip:192.168.2.11
sip registrar ip:192.168.2.11
sip backup proxy ip:192.168.1.11
sip backup registrar ip:192.168.1.11
sip backup proxy port:5060
sip backup registrar port:5060
For Fanvil SIP-phones will be generated a different MAC config file 0c383e777777.txt:
#<Voip Config File>#
Version = 2.0000000000
sip.line.1.PhoneNumber = 7777
sip.line.1.DisplayName = 7777
sip.line.1.RegUser = 7777
sip.line.1.SipName = 192.168.2.11
sip.line.1.RegAddr = 192.168.2.11
sip.line.1.RegPswd = wz5lGPPu6LmRmQ
sip.line.1.RegEnabled = 1
sip.line.1.ProxyAddr = 192.168.2.11
sip.line.1.BackupRegAddr = 192.168.1.11
sip.line.1.BackupProxyAddr = 192.168.1.11
1111,GCkXtXQyDlmTQA
2222,ehbeYGzEjtSGf8
3333,zwbpJ8Wzkjdk3w
4444,vHgddJkbEfIcpn
5555,dmlac2HE98Go3V
6666,nzzkMtPYaItgQ5
7777,wz5lGPPu6LmRmQ
printf '\nCreating extensions...\n'
extension -i -d 1111 --csp 0 -l 1
extension -i -d 2222 --csp 2 -l 1
extension -i -d 3333 --csp 3 -l 1
extension -i -d 4444 --csp 4 -l 2
extension -i -d 5555 --csp 5 -l 2
extension -i -d 6666 --csp 6 -l 2
extension -i -d 7777 --csp 1 -l 2 --third-party-client yes
printf '\nCreating ip-extensions...\n'
ip_extension -i -d 1111 --protocol sip
ip_extension -i -d 2222 --protocol sip
ip_extension -i -d 3333 --protocol sip
ip_extension -i -d 4444 --protocol sip
ip_extension -i -d 5555 --protocol sip
ip_extension -i -d 6666 --protocol sip
ip_extension -i -d 7777 --protocol sip
printf '\nCreating names...\n'
name -i -d 1111 --name1 "First Name" --name2 "Second name" --number-type dir
name -i -d 2222 --name1 "F." --name2 "SEC" --number-type dir
name -i -d 3333 --name1 "First only" --number-type dir
name -i -d 4444 --name1 "First name verylongl" --name2 "Second veryverylongn" --number-type dir
name -i -d 5555 --name2 "Only second" --number-type dir
name -i -d 7777 --name1 "Fanvil" --number-type dir
printf '\nCreating auth codes...\n'
auth_code -i -d 1111 --csp 0 --cil 1111 --customer 0 --hash-type md5a1 --auth-code GCkXtXQyDlmTQA
auth_code -i -d 2222 --csp 2 --cil 2222 --customer 0 --hash-type md5a1 --auth-code ehbeYGzEjtSGf8
auth_code -i -d 3333 --csp 3 --cil 3333 --customer 0 --hash-type md5a1 --auth-code zwbpJ8Wzkjdk3w
auth_code -i -d 4444 --csp 4 --cil 4444 --customer 0 --hash-type md5a1 --auth-code vHgddJkbEfIcpn
auth_code -i -d 5555 --csp 5 --cil 5555 --customer 0 --hash-type md5a1 --auth-code dmlac2HE98Go3V
auth_code -i -d 6666 --csp 6 --cil 6666 --customer 0 --hash-type md5a1 --auth-code nzzkMtPYaItgQ5
auth_code -i -d 7777 --csp 1 --cil 7777 --customer 0 --hash-type md5a1 --auth-code wz5lGPPu6LmRmQThe option "--third-party-client yes" will be added for non-Mitel MAC-addresses.
Note: The extensions.sh file should be prepared with Linux lines end format (LF). You can convert the shell script from Windows (CR LR) format using Linux utility dos2unix in MX-ONE CLI before execution. (The script automatically generate the shell file with Linux LF end).
mx-one$ sh ./extensions.shFor enhanced security, the generated configuration (cfg) files can be encrypted using the anacrypt utility. After encryption, the configuration files are stored as tuz files, which are then uploaded to the Configuration Server, replacing the original unencrypted cfg files.
The anacrypt utility, available from the Mitel SW Download Center, allows you to securely encrypt configuration files for SIP phones. It encrypts all cfg files in the current directory (./) into tuz format using a specified password.
anacrypt -d ./ -m -p password1234 -i-
Encrypt Configuration Files: Use the
anacryptutility to encrypt allcfgfiles in the current directory intotuzfiles. This ensures that the configuration data is protected. -
Copy Encrypted Files: After encryption, transfer the generated
tuzfiles, along with the createdsecurity.tuzfile, to the Configuration Server. -
Download and Decrypt: The SIP phone will then download the encrypted
tuzfiles from the IP Phone Configuration Server, decrypt them using the provided password, and automatically apply the configuration.
The password for encryption will be read by the python script from the local file with the name key_mitel.
For Fanvil phones is used dsc.exe encryption utility with a key stored in a key_fanvil local file.
Then copy all files to a remote config server using scp.
This process ensures secure and efficient registration and configuration of SIP phones on the MX-ONE PBX, leveraging automated scripts and encryption for added security.
Configuration:
BOARD = "1A-0-00-%s"
START_PORT = 0
END_PORT = 31
START_EXT = 200
Run the script:
python extei.py
EXTEI:DIR=200,TYPE=EL6,EQU=1A-0-00-0,CSP=0,ICAT=8020000;
EXTEI:DIR=201,TYPE=EL6,EQU=1A-0-00-1,CSP=0,ICAT=8020000;
EXTEI:DIR=202,TYPE=EL6,EQU=1A-0-00-2,CSP=0,ICAT=8020000;
MAC,EXTENTION,CSP
14:00:E9:11:11:11,101,0
14:00:E9:11:11:12,102,0
14:00:E9:11:11:13,103,1
The script allows you to configure the input CSV file separator, choose the desired password length and SIP proxy IP address.
DELIM = "," # CSV file separator
DIG = 14 # length of auth code
SIP_PROXY = "192.168.1.11"Run the script:
$ python gen_ext_conf_v1.py
Generated 3 config files
<MAC>.cfgfiles<MAC>.tuzencrypted files- file with passwords:
auth-<date-time>.txt - file with commands:
extensions-<date-time>.sh
sip line1 user name:101
sip line1 auth name:101
sip line1 password:n0l0VoB11QNkxU
sip proxy ip:"192.168.1.11"
sip registrar ip:"192.168.1.11"
101,n0l0VoB11QNkxU
102,pY9BwjbJHXVmFq
103,Y6cN2O144k7QyX
extension -i -d 101 --csp 0 -l 1
extension -i -d 102 --csp 0 -l 1
extension -i -d 103 --csp 1 -l 1
ip_extension -i -d 101 --protocol sip
ip_extension -i -d 102 --protocol sip
ip_extension -i -d 103 --protocol sip
auth_code -i -d 101 --csp 0 --cil 101 --customer 0 --hash-type md5a1 --auth-code n0l0VoB11QNkxU
auth_code -i -d 102 --csp 0 --cil 102 --customer 0 --hash-type md5a1 --auth-code pY9BwjbJHXVmFq
auth_code -i -d 103 --csp 1 --cil 103 --customer 0 --hash-type md5a1 --auth-code Y6cN2O144k7QyX



