Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: python3-pyOpenSSL from EPEL 10.3 requires python3-cryptography less than version 49. python3-cryptography was upgraded in CentOS 10 to version 49.0.0. Having python3-pyOpenSSL installed now blocks system upgrades. Version-Release number of selected component (if applicable): python3-pyOpenSSL-25.0.0-1.el10_1 How reproducible: always Steps to Reproduce: 1. dnf install python3-pyOpenSSL 2. dnf upgrade Actual results: Error: Problem: package python3-pyOpenSSL-26.2.0-2.el10_3.noarch from @System requires (python3.12dist(cryptography) < 49~~ with python3.12dist(cryptography) >= 46), but none of the providers can be installed - cannot install both python3-cryptography-49.0.0-1.el10.x86_64 from baseos and python3-cryptography-48.0.0-3.el10.x86_64 from @System - cannot install both python3-cryptography-49.0.0-1.el10.x86_64 from baseos and python3-cryptography-48.0.0-3.el10.x86_64 from baseos - cannot install the best update candidate for package python3-pyOpenSSL-26.2.0-2.el10_3.noarch - cannot install the best update candidate for package python3-cryptography-48.0.0-3.el10.x86_64 Expected results: successful upgrade Additional info: This is similar to bug 2482444, when python3-cryptography was updated to version 48.0.0.
This bug is blocking upgrades on RHEL 10.2: $ sudo dnf upgrade Error: Problem: cannot install the best update candidate for package python3-pyOpenSSL-25.0.0-1.el10_1.noarch - nothing provides (python3.12dist(cryptography) < 49~~ with python3.12dist(cryptography) >= 46) needed by python3-pyOpenSSL-26.2.0-2.el10_3.noarch from rhel-10-epel (try to add '--skip-broken' to skip uninstallable packages or '--nobest' to use not only best candidate packages) Please fix ASAP.
FEDORA-EPEL-2026-91831c24d9 (pyOpenSSL-26.3.0-1.el10_3) has been submitted as an update to Fedora EPEL 10.3. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-91831c24d9
Not really an epel expert, but I'm not sure you want to be using epel 10.3 with rhel 10.2. In any case, I've updated pyOpenSSL in 10.3. Be aware there are some backwards incompatible changes in pyOpenSSL 26.3.
FEDORA-EPEL-2026-91831c24d9 has been pushed to the Fedora EPEL 10.3 testing repository. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-91831c24d9 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
Jeremy is correct. Your system is misconfigured Daniel. EPEL 10 introduced minor versions. Facilitating this required several infrastructure changes. The default experience using the epel-release package accounts for these changes and works out of the box on both RHEL and CentOS. If you are consuming EPEL in some way other than epel-release you'll need to account for these changes yourself to ensure you get the correct content for your distribution. The example baseurl given in epel-release is: https://download.example/pub/epel/$releasever${releasever_minor:+z}/Everything/$basearch/ The DNF variable releasever_minor is defined on RHEL, but not defined on CentOS. On RHEL, that results in a path using pub/epel/10z, which is a symlink on the mirrors to the EPEL minor version built against RHEL. On CentOS, that results in a path using pub/epel/10, which is a symlink on the mirrors to the EPEL minor version built against CentOS. These symlinks are adjusted over time as the minor versions increment. Currently they are as follows: RHEL: pub/epel/10z -> pub/epel/10.2 CentOS: pub/epel/10 -> pub/epel/10.3 If you're setting up a private mirror for a single path, you'll need to sync the appropriate path. Since you stated that you're trying to upgrade to RHEL 10.2, but your error shows a package release with the string el10_3, I suspect you have configured a private mirror to sync pub/epel/10, resulting in your server being presented with EPEL 10.3 content. If you switch that to sync pub/epel/10z and remove extraneous files, your upgrade should work smoothly. Alternatively, you can sync the minor version paths directly if you want more granular control. This can be useful if you have systems still using older minor versions. If you're setting up a private mirror for all of EPEL as described in the Fedora Wiki, you'll already have the necessary symlink structure on your end. This will let you directly adapt epel-release's example baseurl by replacing the download.example domain with your own. https://fedoraproject.org/wiki/Infrastructure/Mirroring
Carl, thank you for the detailed explanation. We are indeed using a private EPEL mirror. This worked perfectly for years on RHEL 7/8/9/10 until this week. Changing the behavior of a widely used and longstanding url is a recipe for frustration. Everyone who isn't in the loop has to spend valuable time troubleshooting and fixing their systems; see Ben Erickson's comments in Bug 2492226. After updating our mirrors to use epel/10z instead of epel/10, dnf upgrade is working again. Thanks again for the helpful response and recommendations.
FEDORA-EPEL-2026-91831c24d9 (pyOpenSSL-26.3.0-1.el10_3) has been pushed to the Fedora EPEL 10.3 stable repository. If problem still persists, please make note of it in this bug report.