Bug 2521652

Summary: python3-cryptography conflict when attempting to update to latest version of pyOpenSSL
Product: [Fedora] Fedora EPEL Reporter: Jody <jody+redhat>
Component: distributionAssignee: Carl George 🤠 <carlwgeorge>
Status: CLOSED COMPLETED QA Contact:
Severity: urgent Docs Contact:
Priority: unspecified    
Version: epel10CC: carlwgeorge, crypto-team, jean-louis, jeremy, jonathan, kevin, paul.wouters, tm
Target Milestone: ---Flags: fedora-admin-xmlrpc: mirror+
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-08-26 19:28:29 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Jody 2026-08-23 16:58:19 UTC
OS version is RHEL 10.2.  epel-release on my system was just upgraded from epel-release-10-8.el10_2.noarch to epel-release-10-9.el10_3.noarch.  I have python3-pyOpenSSL-26.3.0-1.el10_3 available as an update.  I get the following error that breaks updating.

Error:
 Problem: cannot install the best update candidate for package python3-pyOpenSSL-25.0.0-1.el10_1.noarch
  - nothing provides (python3.12dist(cryptography) < 50~~ with python3.12dist(cryptography) >= 49) needed by python3-pyOpenSSL-26.3.0-1.el10_3.noarch from epel

Comment 1 Carl George 🤠 2026-08-26 17:28:02 UTC
epel-release-10-9.el10_3 has only been published in EPEL 10.3+.  A properly configured RHEL 10.2 system should only be seeing EPEL 10.2 and won't get that epel-release update yet.  My guess is you're not actually using epel-release repos (which would be configured correctly out of the box) and are somehow consuming EPEL 10.3 directly.  That would also explain why you're seeing python3-pyOpenSSL-26.3.0-1.el10_3, which again has only been published for EPEL 10.3+.  Do you have EPEL configured through a private mirror, satellite, or some other kind of repo file?

Comment 2 Jody 2026-08-26 18:16:31 UTC
I'm using EPEL installed using the RHEL 10 instructions at https://docs.fedoraproject.org/en-US/epel/getting-started/.

Here's the contents of my epel.repo file:

[epel]
name=Extra Packages for Enterprise Linux $releasever - $basearch
# It is much more secure to use the metalink, but if you wish to use a local mirror
# place its address here.
#baseurl=https://download.example/pub/epel/$releasever${stream:+s}/Everything/$basearch/
metalink=https://mirrors.fedoraproject.org/metalink?repo=epel-$releasever${stream:+s}&arch=$basearch
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-$releasever_major
gpgcheck=1
repo_gpgcheck=0
metadata_expire=24h
countme=1
enabled=1

This is a vanilla EPEL install on RHEL 10.2.

Comment 3 Jody 2026-08-26 18:26:10 UTC
You guys have some broken stuff.  Something leaked.

# cat /etc/redhat-release
Red Hat Enterprise Linux release 10.2 (Coughlan)

# dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-10.noarch.rpm
Updating Subscription Management repositories.
Last metadata expiration check: 0:03:01 ago on Wed 26 Aug 2026 12:21:24 PM CST.
epel-release-latest-10.noarch.rpm                                                                                               107 kB/s |  19 kB     00:00
Dependencies resolved.
================================================================================================================================================================
 Package                                 Architecture                      Version                                Repository                               Size
================================================================================================================================================================
Installing:
 epel-release                            noarch                            10-9.el10_3                            @commandline                             19 k

Transaction Summary
================================================================================================================================================================
Install  1 Package

Comment 4 Carl George 🤠 2026-08-26 19:28:29 UTC
For background context, EPEL 10 introduced minor version repos.  One of the overall goals was to use a unified epel-release package for both CentOS and RHEL, even though they consume different minor version repos.  Originally we achieved this by using a metalink that evaluated the repo to epel-z-10 on RHEL, and epel-10 on CentOS.  This made the most sense from the infrastructure perspective, but has caused confusion for people running private mirrors.  To solve this we're transitioning it to a new metalink that evaluates to epel-10 on RHEL and epel-10s on CentOS.  That has been implemented in the epel-release-10-9.el10_3 package.

https://discussion.fedoraproject.org/t/looking-back-at-epel-10-and-forward-to-epel-11/197373/17

Since you confirmed that you ended up with this epel-release package installed by following the normal installation procedure, I took a closer look at that route.  I discovered that the epel-release-latest-10.noarch.rpm symlink on the mirrors was incorrectly set to 10.4/Everything/x86_64/Packages/e/epel-release-10-9.el10_3.noarch.rpm due to a bug in one of our automation scripts (new-updates-sync).  It should still be set to 10.2/Everything/x86_64/Packages/e/epel-release-10-8.el10_2.noarch.rpm, so I manually reverted it to that.  I've also commented out the relevant line of that script and will work on a longer term fix.

You can fix your system by manually downgrading the installed epel-release package.  You may also need to clean your dnf cache afterwards.

    dnf install https://dl.fedoraproject.org/pub/epel/10.2/Everything/x86_64/Packages/e/epel-release-10-8.el10_2.noarch.rpm
    dnf clean all

Thanks for bringing this to our attention and sorry for the inconvenience.