EPEL and Third-Party Repositories
Applies to CentOS Stream 9 & 10 / AlmaLinux 9.x & 10.x / Rocky Linux 9.x & 10.x
The official EL repositories prioritize stability and include a limited number of packages. EPEL and other third-party repositories can significantly expand the range of available software. This article explains how to use these repositories safely.
What You Will Learn
Section titled “What You Will Learn”- What EPEL is and why you need it
- How to install and enable EPEL
- Other commonly used third-party repositories (RPM Fusion, Remi, ELRepo)
- Security considerations when using third-party repositories
Prerequisites
Section titled “Prerequisites”- A system with EL 9.x installed
- A user account with
sudoprivileges - The system is connected to the internet
- Familiarity with DNF Basics and Repository Management
What is EPEL
Section titled “What is EPEL”EPEL (Extra Packages for Enterprise Linux) is a supplementary software repository maintained by the Fedora community. It provides high-quality packages for RHEL/EL systems that are not available in the official repositories.
Key characteristics of EPEL:
- Reliable: Officially maintained by the Fedora Project with quality assurance
- Extensive: Provides thousands of additional packages
- Secure: All packages are GPG-signed
- Compatible: Does not replace packages from the official repositories; serves only as a supplement
Common EPEL-exclusive packages include: htop, neofetch, certbot, fail2ban, ansible, and more.
Installing EPEL
Section titled “Installing EPEL”-
Enable the CRB repository
Many packages in EPEL depend on development libraries from the CRB (CodeReady Builder) repository, so it is recommended to enable it first:
Enable the CRB repository $ sudo dnf config-manager --set-enabled crb -
Install EPEL
Install the EPEL repository $ sudo dnf install -y epel-release -
Verify the installation
Confirm EPEL is enabled $ dnf repolist | grep epelExample output:
epel Extra Packages for Enterprise Linux 9 - x86_64 -
Refresh the cache
Update the metadata cache $ sudo dnf makecache
Using Packages from EPEL
Section titled “Using Packages from EPEL”Once EPEL is installed, you can install packages from it just like you would from the official repositories:
$ sudo dnf install htop$ dnf search --repo=epel fail2ban$ dnf list available --repo=epel | head -30$ dnf info htopIn the output, the Repository field will show epel.
Installing Only from EPEL
Section titled “Installing Only from EPEL”If you want to install a package exclusively from EPEL (avoiding other repositories):
$ sudo dnf install --repo=epel certbotRPM Fusion
Section titled “RPM Fusion”RPM Fusion provides software that the Fedora and EL official repositories cannot include due to licensing or patent restrictions, such as multimedia codecs and proprietary drivers.
RPM Fusion consists of two repositories:
- free: Open-source software that is not included in the official repositories for other reasons
- nonfree: Non-free/proprietary software
-
Install the RPM Fusion free repository
Install RPM Fusion free $ sudo dnf install -y \https://mirrors.rpmfusion.org/free/el/rpmfusion-free-release-$(rpm -E %{rhel}).noarch.rpm -
Install the RPM Fusion nonfree repository (optional)
Install RPM Fusion nonfree $ sudo dnf install -y \https://mirrors.rpmfusion.org/nonfree/el/rpmfusion-nonfree-release-$(rpm -E %{rhel}).noarch.rpm -
Verify
Confirm RPM Fusion repositories have been added $ dnf repolist | grep rpmfusionExample output:
rpmfusion-free-updates RPM Fusion for EL 9 - Free - Updatesrpmfusion-nonfree-updates RPM Fusion for EL 9 - Nonfree - Updates
Remi Repository
Section titled “Remi Repository”The Remi repository is maintained by Remi Collet and primarily provides the latest versions of PHP and related extensions. It is an essential tool for PHP developers.
-
Install the Remi repository
Install the Remi repository $ sudo dnf install -y \https://rpms.remirepo.net/enterprise/remi-release-$(rpm -E %{rhel}).rpm -
View available PHP versions
List PHP module streams provided by Remi $ dnf module list phpExample output:
Remi's Modular repository for Enterprise Linux 9 - x86_64Name Stream Profiles Summaryphp remi-8.1 common [d], devel, minimal PHP scripting languagephp remi-8.2 common [d], devel, minimal PHP scripting languagephp remi-8.3 common [d], devel, minimal PHP scripting languagephp remi-8.4 common [d], devel, minimal PHP scripting language -
Enable a specific PHP version and install
EL 9 (module streams available):
Reset the PHP module and enable PHP 8.3 $ sudo dnf module reset php$ sudo dnf module enable php:remi-8.3$ sudo dnf install -y php php-cli php-fpm php-mysqlnd php-opcacheEL 10 (no modular content — install the versioned packages directly):
EL 10: install PHP 8.3 packages from Remi directly $ sudo dnf install -y php83 php83-php-cli php83-php-fpm php83-php-mysqlnd php83-php-opcache -
Verify
Confirm the PHP version $ php -v
ELRepo
Section titled “ELRepo”ELRepo focuses on hardware-related packages, including kernel modules, graphics drivers, and other hardware drivers.
-
Import the GPG key
Import the ELRepo GPG key $ sudo rpm --import https://www.elrepo.org/RPM-GPG-KEY-elrepo.org -
Install ELRepo
Install the ELRepo repository $ sudo dnf install -y \https://www.elrepo.org/elrepo-release-9.el9.elrepo.noarch.rpm -
View available kernel packages
The most common use of ELRepo is to provide the latest mainline kernel (kernel-ml) and long-term support kernel (kernel-lt):
View available kernel packages in ELRepo $ dnf list available --repo=elrepo-kernel
Using Third-Party Repositories Safely
Section titled “Using Third-Party Repositories Safely”Choose Trusted Repositories
Section titled “Choose Trusted Repositories”Not all third-party repositories are trustworthy. When selecting a repository, consider:
- Maintainer reputation: Is it maintained by a well-known individual or organization?
- Community recognition: Is it widely used and recommended?
- Update frequency: Is it actively maintained?
- GPG signing: Are all packages signed?
Always Enable GPG Verification
Section titled “Always Enable GPG Verification”$ grep -r "gpgcheck" /etc/yum.repos.d/ | grep "gpgcheck=0"If any repository has GPG checking disabled, change gpgcheck=0 to gpgcheck=1.
Use Repository Priorities
Section titled “Use Repository Priorities”Prevent third-party repository packages from overriding official packages:
$ sudo dnf config-manager --save --setopt=epel.priority=20Exclude Specific Packages
Section titled “Exclude Specific Packages”If you do not want a third-party repository to affect certain packages, use the exclude configuration:
$ sudo vi /etc/yum.repos.d/epel.repoAdd the following under the [epel] section:
exclude=kernel* kmod*Periodically Audit Repositories
Section titled “Periodically Audit Repositories”$ dnf list installed | awk '{print $3}' | sort | uniq -c | sort -rn$ dnf list installed --repo=epelCommon Issues
Section titled “Common Issues”EPEL Installation Error: “No match for argument”
Section titled “EPEL Installation Error: “No match for argument””On some minimal installations, you may need to install epel-release from the base repository first:
$ sudo dnf install -y epel-releaseIf that still fails, install the RPM manually:
$ sudo dnf install -y \ https://dl.fedoraproject.org/pub/epel/epel-release-latest-9.noarch.rpmThird-Party Packages Conflict with Official Repository Packages
Section titled “Third-Party Packages Conflict with Official Repository Packages”If you encounter package conflicts:
$ dnf info <package-name>$ sudo dnf install -y python3-dnf-plugin-versionlock$ sudo dnf versionlock add <package-name>$ dnf versionlock listHow to Completely Remove a Third-Party Repository
Section titled “How to Completely Remove a Third-Party Repository”$ sudo dnf remove epel-release$ sudo rm -f /etc/yum.repos.d/epel*.repo$ sudo dnf clean allFurther Reading
Section titled “Further Reading”- Repository Management — Detailed repository configuration
- DNF Package Management Basics — Everyday package management operations
- RPM Basics — Low-level package management tool
- EPEL official wiki: https://docs.fedoraproject.org/en-US/epel/
- Remi repository website: https://rpms.remirepo.net/
EL 10 Notes: EPEL 10
Section titled “EL 10 Notes: EPEL 10”EPEL 10 is a separate repository from EPEL 9. Key differences:
- Fewer packages initially: EPEL 10 starts with significantly fewer packages than EPEL 9 — some common tools may not yet be ported
- Same installation method: Running
dnf install epel-releaseon an EL 10 system automatically installs EPEL 10 - Third-party repos (Remi, RPM Fusion): EL 10 support may lag — check availability before use
$ sudo dnf install -y epel-release$ dnf repolist | grep epel# Output should show "Extra Packages for Enterprise Linux 10"