Bug 2521652 - python3-cryptography conflict when attempting to update to latest version of pyOpenSSL
Summary: python3-cryptography conflict when attempting to update to latest version of ...
Keywords:
Status: CLOSED COMPLETED
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: distribution
Version: epel10
Hardware: x86_64
OS: Linux
unspecified
urgent
Target Milestone: ---
Assignee: Carl George 🤠
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-23 16:58 UTC by Jody
Modified: 2026-08-26 19:28 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-08-26 19:28:29 UTC
Type: Bug
Embargoed:
fedora-admin-xmlrpc: mirror+


Attachments (Terms of Use)

Description Jody 2026-08-23 16:58:19 UTC
OS version is RHEL 10.2.  epel-release on my system was just upgraded from epel-release-10-8.el10_2.noarch to epel-release-10-9.el10_3.noarch.  I have python3-pyOpenSSL-26.3.0-1.el10_3 available as an update.  I get the following error that breaks updating.

Error:
 Problem: cannot install the best update candidate for package python3-pyOpenSSL-25.0.0-1.el10_1.noarch
  - nothing provides (python3.12dist(cryptography) < 50~~ with python3.12dist(cryptography) >= 49) needed by python3-pyOpenSSL-26.3.0-1.el10_3.noarch from epel

Comment 1 Carl George 🤠 2026-08-26 17:28:02 UTC
epel-release-10-9.el10_3 has only been published in EPEL 10.3+.  A properly configured RHEL 10.2 system should only be seeing EPEL 10.2 and won't get that epel-release update yet.  My guess is you're not actually using epel-release repos (which would be configured correctly out of the box) and are somehow consuming EPEL 10.3 directly.  That would also explain why you're seeing python3-pyOpenSSL-26.3.0-1.el10_3, which again has only been published for EPEL 10.3+.  Do you have EPEL configured through a private mirror, satellite, or some other kind of repo file?

Comment 2 Jody 2026-08-26 18:16:31 UTC
I'm using EPEL installed using the RHEL 10 instructions at https://docs.fedoraproject.org/en-US/epel/getting-started/.

Here's the contents of my epel.repo file:

[epel]
name=Extra Packages for Enterprise Linux $releasever - $basearch
# It is much more secure to use the metalink, but if you wish to use a local mirror
# place its address here.
#baseurl=https://download.example/pub/epel/$releasever${stream:+s}/Everything/$basearch/
metalink=https://mirrors.fedoraproject.org/metalink?repo=epel-$releasever${stream:+s}&arch=$basearch
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-$releasever_major
gpgcheck=1
repo_gpgcheck=0
metadata_expire=24h
countme=1
enabled=1

This is a vanilla EPEL install on RHEL 10.2.

Comment 3 Jody 2026-08-26 18:26:10 UTC
You guys have some broken stuff.  Something leaked.

# cat /etc/redhat-release
Red Hat Enterprise Linux release 10.2 (Coughlan)

# dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-10.noarch.rpm
Updating Subscription Management repositories.
Last metadata expiration check: 0:03:01 ago on Wed 26 Aug 2026 12:21:24 PM CST.
epel-release-latest-10.noarch.rpm                                                                                               107 kB/s |  19 kB     00:00
Dependencies resolved.
================================================================================================================================================================
 Package                                 Architecture                      Version                                Repository                               Size
================================================================================================================================================================
Installing:
 epel-release                            noarch                            10-9.el10_3                            @commandline                             19 k

Transaction Summary
================================================================================================================================================================
Install  1 Package

Comment 4 Carl George 🤠 2026-08-26 19:28:29 UTC
For background context, EPEL 10 introduced minor version repos.  One of the overall goals was to use a unified epel-release package for both CentOS and RHEL, even though they consume different minor version repos.  Originally we achieved this by using a metalink that evaluated the repo to epel-z-10 on RHEL, and epel-10 on CentOS.  This made the most sense from the infrastructure perspective, but has caused confusion for people running private mirrors.  To solve this we're transitioning it to a new metalink that evaluates to epel-10 on RHEL and epel-10s on CentOS.  That has been implemented in the epel-release-10-9.el10_3 package.

https://discussion.fedoraproject.org/t/looking-back-at-epel-10-and-forward-to-epel-11/197373/17

Since you confirmed that you ended up with this epel-release package installed by following the normal installation procedure, I took a closer look at that route.  I discovered that the epel-release-latest-10.noarch.rpm symlink on the mirrors was incorrectly set to 10.4/Everything/x86_64/Packages/e/epel-release-10-9.el10_3.noarch.rpm due to a bug in one of our automation scripts (new-updates-sync).  It should still be set to 10.2/Everything/x86_64/Packages/e/epel-release-10-8.el10_2.noarch.rpm, so I manually reverted it to that.  I've also commented out the relevant line of that script and will work on a longer term fix.

You can fix your system by manually downgrading the installed epel-release package.  You may also need to clean your dnf cache afterwards.

    dnf install https://dl.fedoraproject.org/pub/epel/10.2/Everything/x86_64/Packages/e/epel-release-10-8.el10_2.noarch.rpm
    dnf clean all

Thanks for bringing this to our attention and sorry for the inconvenience.


Note You need to log in before you can comment on or make changes to this bug.