Bug 2494597 - python3-pyOpenSSL: dependency problem in EPEL 10.3
Summary: python3-pyOpenSSL: dependency problem in EPEL 10.3
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: pyOpenSSL
Version: epel10
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Paul Wouters
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-29 18:28 UTC by Carl George 🤠
Modified: 2026-07-12 00:27 UTC (History)
7 users (show)

Fixed In Version: pyOpenSSL-26.3.0-1.el10_3
Clone Of:
Environment:
Last Closed: 2026-07-12 00:27:01 UTC
Type: Bug
Embargoed:
fedora-admin-xmlrpc: mirror+


Attachments (Terms of Use)

Description Carl George 🤠 2026-06-29 18:28:35 UTC
Description of problem:
python3-pyOpenSSL from EPEL 10.3 requires python3-cryptography less than version 49.  python3-cryptography was upgraded in CentOS 10 to version 49.0.0.  Having python3-pyOpenSSL installed now blocks system upgrades.


Version-Release number of selected component (if applicable):
python3-pyOpenSSL-25.0.0-1.el10_1


How reproducible:
always


Steps to Reproduce:
1. dnf install python3-pyOpenSSL
2. dnf upgrade


Actual results:
Error: 
 Problem: package python3-pyOpenSSL-26.2.0-2.el10_3.noarch from @System requires (python3.12dist(cryptography) < 49~~ with python3.12dist(cryptography) >= 46), but none of the providers can be installed
  - cannot install both python3-cryptography-49.0.0-1.el10.x86_64 from baseos and python3-cryptography-48.0.0-3.el10.x86_64 from @System
  - cannot install both python3-cryptography-49.0.0-1.el10.x86_64 from baseos and python3-cryptography-48.0.0-3.el10.x86_64 from baseos
  - cannot install the best update candidate for package python3-pyOpenSSL-26.2.0-2.el10_3.noarch
  - cannot install the best update candidate for package python3-cryptography-48.0.0-3.el10.x86_64


Expected results:
successful upgrade


Additional info:
This is similar to bug 2482444, when python3-cryptography was updated to version 48.0.0.

Comment 1 Daniel Bakken 2026-07-08 15:33:58 UTC
This bug is blocking upgrades on RHEL 10.2:

$ sudo dnf upgrade

Error: 
 Problem: cannot install the best update candidate for package python3-pyOpenSSL-25.0.0-1.el10_1.noarch
  - nothing provides (python3.12dist(cryptography) < 49~~ with python3.12dist(cryptography) >= 46) needed by python3-pyOpenSSL-26.2.0-2.el10_3.noarch from rhel-10-epel
(try to add '--skip-broken' to skip uninstallable packages or '--nobest' to use not only best candidate packages)

Please fix ASAP.

Comment 2 Fedora Update System 2026-07-08 18:23:40 UTC
FEDORA-EPEL-2026-91831c24d9 (pyOpenSSL-26.3.0-1.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-91831c24d9

Comment 3 Jeremy Cline 2026-07-08 18:27:19 UTC
Not really an epel expert, but I'm not sure you want to be using epel 10.3 with rhel 10.2. In any case, I've updated pyOpenSSL in 10.3. Be aware there are some backwards incompatible changes in pyOpenSSL 26.3.

Comment 4 Fedora Update System 2026-07-09 00:33:33 UTC
FEDORA-EPEL-2026-91831c24d9 has been pushed to the Fedora EPEL 10.3 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-91831c24d9

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Carl George 🤠 2026-07-09 06:14:17 UTC
Jeremy is correct.  Your system is misconfigured Daniel.

EPEL 10 introduced minor versions.  Facilitating this required several infrastructure changes.  The default experience using the epel-release package accounts for these changes and works out of the box on both RHEL and CentOS.  If you are consuming EPEL in some way other than epel-release you'll need to account for these changes yourself to ensure you get the correct content for your distribution.  The example baseurl given in epel-release is:

https://download.example/pub/epel/$releasever${releasever_minor:+z}/Everything/$basearch/

The DNF variable releasever_minor is defined on RHEL, but not defined on CentOS. On RHEL, that results in a path using pub/epel/10z, which is a symlink on the mirrors to the EPEL minor version built against RHEL.  On CentOS, that results in a path using pub/epel/10, which is a symlink on the mirrors to the EPEL minor version built against CentOS.  These symlinks are adjusted over time as the minor versions increment.  Currently they are as follows:

RHEL:   pub/epel/10z -> pub/epel/10.2
CentOS: pub/epel/10  -> pub/epel/10.3

If you're setting up a private mirror for a single path, you'll need to sync the appropriate path.  Since you stated that you're trying to upgrade to RHEL 10.2, but your error shows a package release with the string el10_3, I suspect you have configured a private mirror to sync pub/epel/10, resulting in your server being presented with EPEL 10.3 content.  If you switch that to sync pub/epel/10z and remove extraneous files, your upgrade should work smoothly.  Alternatively, you can sync the minor version paths directly if you want more granular control.  This can be useful if you have systems still using older minor versions.

If you're setting up a private mirror for all of EPEL as described in the Fedora Wiki, you'll already have the necessary symlink structure on your end.  This will let you directly adapt epel-release's example baseurl by replacing the download.example domain with your own.

https://fedoraproject.org/wiki/Infrastructure/Mirroring

Comment 6 Daniel Bakken 2026-07-09 13:41:20 UTC
Carl, thank you for the detailed explanation. We are indeed using a private EPEL mirror. This worked perfectly for years on RHEL 7/8/9/10 until this week. Changing the behavior of a widely used and longstanding url is a recipe for frustration. Everyone who isn't in the loop has to spend valuable time troubleshooting and fixing their systems; see Ben Erickson's comments in Bug 2492226.

After updating our mirrors to use epel/10z instead of epel/10, dnf upgrade is working again. Thanks again for the helpful response and recommendations.

Comment 7 Fedora Update System 2026-07-12 00:27:01 UTC
FEDORA-EPEL-2026-91831c24d9 (pyOpenSSL-26.3.0-1.el10_3) has been pushed to the Fedora EPEL 10.3 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.