Skip to content

Title: RHEL 9.4: OpenSSL FIPS package conflict after cda6a0f revert #1973

Description

@dsariel

Problem

After commit cda6a0f ("Revert openssl version hacks"), dev-scripts fails on RHEL 9.4 systems during 01_install_requirements.sh with:

Transaction test error:
  file /usr/lib64/ossl-modules/fips.so from install of openssl-libs-1:3.0.7-6.el9_2.x86_64
  conflicts with file from package openssl-fips-provider-so-3.0.7-11.el9_0.x86_64

Root cause

The revert in cda6a0f assumed both Python and OpenSSL issues were fixed in CentOS Stream 9. While this is correct for CentOS Stream 9, RHEL 9.4 repositories still ship the conflicting openssl-fips-provider-so package that provides /usr/lib64/ossl-modules/fips.so, which conflicts with newer openssl-libs.

Affected systems

  • RHEL 9.2, 9.3, 9.4 (possibly earlier)
  • Deployments using RHEL repos instead of CentOS Stream 9

Proposed solution

Add conditional handling based on OS detection:

# Handle RHEL-specific OpenSSL FIPS provider conflict
if [[ -f /etc/redhat-release ]] && grep -q "Red Hat Enterprise Linux" /etc/redhat-release; then
    if rpm -q openssl-fips-provider-so &>/dev/null; then
        echo "Removing openssl-fips-provider-so to prevent RHEL 9.x package conflicts..."
        sudo dnf remove -y openssl-fips-provider-so
    fi
fi

This preserves the cda6a0f fix for CentOS Stream while handling RHEL-specific conflicts.

References

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions