Bug 2482444 - python3-pyOpenSSL: dependency problem in EPEL 10.3
Summary: python3-pyOpenSSL: dependency problem in EPEL 10.3
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: pyOpenSSL
Version: epel10
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Paul Wouters
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-28 00:08 UTC by Carl George 🤠
Modified: 2026-06-23 15:42 UTC (History)
6 users (show)

Fixed In Version: pyOpenSSL-26.2.0-2.el10_3
Clone Of:
Environment:
Last Closed: 2026-06-15 22:51:29 UTC
Type: Bug
Embargoed:
fedora-admin-xmlrpc: mirror+


Attachments (Terms of Use)

Description Carl George 🤠 2026-05-28 00:08:15 UTC
Description of problem:
python3-pyOpenSSL from EPEL 10.3 requires python3-cryptography less than version 45.  python3-cryptography was upgraded in CentOS 10 to version 48.0.0.  Having python3-pyOpenSSL installed now blocks system upgrades.


Version-Release number of selected component (if applicable):
python3-pyOpenSSL-25.0.0-1.el10_1


How reproducible:
always


Steps to Reproduce:
1. dnf install python3-pyOpenSSL
2. dnf upgrade


Actual results:
Error: 
 Problem: package python3-pyOpenSSL-25.0.0-1.el10_1.noarch from @System requires (python3.12dist(cryptography) < 45~~ with python3.12dist(cryptography) >= 41.0.5), but none of the providers can be installed
  - cannot install both python3-cryptography-48.0.0-3.el10.x86_64 from baseos and python3-cryptography-43.0.0-4.el10.x86_64 from @System
  - cannot install both python3-cryptography-48.0.0-3.el10.x86_64 from baseos and python3-cryptography-41.0.7-2.el10.x86_64 from baseos
  - cannot install both python3-cryptography-48.0.0-3.el10.x86_64 from baseos and python3-cryptography-43.0.0-2.el10.x86_64 from baseos
  - cannot install both python3-cryptography-48.0.0-3.el10.x86_64 from baseos and python3-cryptography-43.0.0-3.el10.x86_64 from baseos
  - cannot install both python3-cryptography-48.0.0-3.el10.x86_64 from baseos and python3-cryptography-43.0.0-4.el10.x86_64 from baseos
  - cannot install the best update candidate for package python3-pyOpenSSL-25.0.0-1.el10_1.noarch
  - cannot install the best update candidate for package python3-cryptography-43.0.0-4.el10.x86_64


Expected results:
successful upgrade

Comment 1 Gerd v. Egidy 2026-06-15 14:36:09 UTC
This issue hit me too when trying to update from EL 10.1 to 10.2.

To me it looks like there is some typo in the versions or similar, because EL 10.3 is not released yet, we are currently at 10.2.

Comment 2 Carl George 🤠 2026-06-15 20:16:53 UTC
Gerd, I'm not sure why you had an issue on that upgrade.  python3-pyOpenSSL installs correctly and doesn't block upgrades on RHEL 10.2.  It also works fine on RHEL 10.1 if you force it to use EPEL 10.1 by setting releasever to 10.1.

It's not a typo in the versions, EPEL 10.3 exists now and is used on CentOS (which already has RHEL 10.3 content).  Once RHEL 10.3 is released, RHEL users will switch automatically from EPEL 10.2 to EPEL 10.3.  If this issue isn't resolved before then, then it will impact RHEL users, but for now it only impacts CentOS users.

https://bodhi.fedoraproject.org/releases/EPEL-10.3

https://docs.fedoraproject.org/en-US/epel/branches/

Comment 3 Carl George 🤠 2026-06-15 22:51:29 UTC
Looks like this was fixed in pyOpenSSL-26.2.0-2.el10_3, which was promoted to the stable repos a week ago.

https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-b0cb0d62d7

Comment 4 Gerd v. Egidy 2026-06-23 15:00:29 UTC
I figured out what my problem was:

I use a local mirror of EPEL and out of habit I mirrored .../dl.fedoraproject.org/epel/10/ there. But the "10" link now points to "10.3", which contains packages that are designed to just work on 10.3 and not yet on 10.2.

I have now changed my local mirror to .../dl.fedoraproject.org/epel/10.2/ and that fixed it.

Comment 5 Carl George 🤠 2026-06-23 15:42:00 UTC
FYI, if you want your local mirror to follow the RHEL minor versions, you can sync epel/10z instead.


Note You need to log in before you can comment on or make changes to this bug.