Skip to content

EL 10 Changes Overview

This page consolidates the changes most likely to trip you up when migrating from EL 9 to EL 10 (RHEL 10 / AlmaLinux 10 / Rocky Linux 10, released in 2025), as a quick index. Each item links to its detailed documentation.

ChangeEL 9EL 10Impact
Package managerDNF 4DNF 4.20 (still DNF 4, command-compatible)Day-to-day commands largely unchanged
AppStream modularityModule streams availableDeprecated (no modular content; dnf module warns)Version selection changes
Default Python3.93.12Old scripts may break
Network configkeyfile (ifcfg deprecated)keyfile only (ifcfg removed)Leftover ifcfg stops working
Default crypto policyDEFAULT (SHA-1 allowed)SHA-1 disabledOld certs/keys may be rejected
Podman4.x5.xRootless network defaults to pasta
filelists metadataDownloaded by defaultNot downloaded by defaultFile-path queries may need it enabled

EL 10’s package manager is still DNF 4 (currently 4.20, with dnf-plugins-core 4.7.0), not DNF 5; config-manager and other day-to-day commands keep the same syntax as EL 9. The main changes:

  • Modularity deprecated: the dnf module command still exists but prints a deprecation warning, and no modular content is distributed.
  • filelists metadata not downloaded by default: add --setopt=optional_metadata_types=filelists when needed, or set it in /etc/dnf/dnf.conf.
  • DNF debug plugin removed: dnf debug-dump / dnf debug-restore are gone; use dnf list --installed, dnf repoquery --installed, and similar commands instead.
  • libreport support removed.

See DNF Basics.

EL 10 no longer distributes AppStream modular content. The dnf module command still exists but prints a deprecation warning and has no module streams available. The old approach of dnf module enable php:8.1 to pick a version is replaced by installing a versioned package name directly:

Terminal window
# EL 9
sudo dnf module enable php:8.1 && sudo dnf install php
# EL 10: install the versioned package directly (as the repo provides it)
sudo dnf install php

Any automation that relies on dnf module must be adapted before upgrading. Third-party repos (e.g. Remi) also move from module streams to versioned package names — see EPEL & Third-Party and Redis.

The default system Python moves to 3.12. Note that the EL 10 system Python is meant for system components only; isolate application code in virtual environments (venv) to avoid affecting the system toolchain.

The ifcfg-* scripts — deprecated but still supported on EL 9 — are removed entirely on EL 10. NetworkManager only accepts the keyfile format (/etc/NetworkManager/system-connections/). Convert any leftover ifcfg config with nmcli connection migrate before upgrading. See NetworkManager Basics.

EL 10’s DEFAULT crypto policy disables SHA-1 signatures by default. Old SHA-1-based certificates and SSH keys may be rejected. Switch to SHA-256+ certificates and generate Ed25519 SSH keys before upgrading. See SSH Hardening.

EL 10 ships Podman 5.x, and the rootless container network default changes from slirp4netns to pasta. The official recommendation is now to use Quadlet for systemd integration (podman generate systemd is deprecated).

EL 10 still provides versionlock through dnf-plugin-versionlock, and the config file remains /etc/dnf/plugins/versionlock.list — it does not move to versionlock.toml. Lock rules carried over from EL 9 keep working, but make sure the pinned versions actually exist in the EL 10 repositories. See Version Locking.