Problem
After commit cda6a0f ("Revert openssl version hacks"), dev-scripts fails on RHEL 9.4 systems during 01_install_requirements.sh with:
Transaction test error:
file /usr/lib64/ossl-modules/fips.so from install of openssl-libs-1:3.0.7-6.el9_2.x86_64
conflicts with file from package openssl-fips-provider-so-3.0.7-11.el9_0.x86_64
Root cause
The revert in cda6a0f assumed both Python and OpenSSL issues were fixed in CentOS Stream 9. While this is correct for CentOS Stream 9, RHEL 9.4 repositories still ship the conflicting openssl-fips-provider-so package that provides /usr/lib64/ossl-modules/fips.so, which conflicts with newer openssl-libs.
Affected systems
- RHEL 9.2, 9.3, 9.4 (possibly earlier)
- Deployments using RHEL repos instead of CentOS Stream 9
Proposed solution
Add conditional handling based on OS detection:
# Handle RHEL-specific OpenSSL FIPS provider conflict
if [[ -f /etc/redhat-release ]] && grep -q "Red Hat Enterprise Linux" /etc/redhat-release; then
if rpm -q openssl-fips-provider-so &>/dev/null; then
echo "Removing openssl-fips-provider-so to prevent RHEL 9.x package conflicts..."
sudo dnf remove -y openssl-fips-provider-so
fi
fi
This preserves the cda6a0f fix for CentOS Stream while handling RHEL-specific conflicts.
References
Problem
After commit cda6a0f ("Revert openssl version hacks"), dev-scripts fails on RHEL 9.4 systems during
01_install_requirements.shwith:Root cause
The revert in cda6a0f assumed both Python and OpenSSL issues were fixed in CentOS Stream 9. While this is correct for CentOS Stream 9, RHEL 9.4 repositories still ship the conflicting
openssl-fips-provider-sopackage that provides/usr/lib64/ossl-modules/fips.so, which conflicts with neweropenssl-libs.Affected systems
Proposed solution
Add conditional handling based on OS detection:
This preserves the cda6a0f fix for CentOS Stream while handling RHEL-specific conflicts.
References