Global InfraGlobal Infra Cloud

Workspace Configuration

Configure DNS, proxy, certificates, and SSH keys for your workspace

Edit

DNS

All devices configured by GI (Linux/Windows laptops and AWS Workstations) are already configured to use Global Infra DNS servers.

If you are using a DWS or your own laptop, you can configure a local DNS server that forwards name resolution of Global Infra zones to GI DNS servers.

Internet Proxy

Configure proxy in your browser:

SettingValue
HTTP/SSL Proxy (EMEA)proxy-wks.services.core.pr.eu.ginfra.net:3128
HTTP/SSL Proxy (APAC)proxy-wks.services.core.pr.au.ginfra.net:3128
No Proxylocalhost, 127.0.0.1, *.lab.ingenico.com, 10.*, 172.*, *.its, *.ginfra.net, *.giservices.io, ingenico.okta-emea.com

This is enforced by Puppet Configuration Management and should already be set correctly on managed devices.

Certificate Management

If you are using laptops managed by Global Infra, you can skip this section.

When using devices not managed by GI, you may face certificate issues:

  1. GitLab is signed with a public CA but may not be recognized by older browsers. Install the CA for GitLab at the system or browser level.
  2. GI services use a CA per platform. Install the Global Infra Intermediate CA:
    • IngenicoGlobal-InfraSharedSandboxIntermediateCA.crt
    • IngenicoGlobal-InfraSharedPreprodIntermediateCA.crt
    • IngenicoGlobal-InfraSharedProdIntermediateCA.crt

SSH Key Management

To authenticate on production servers through IPA, generate your own SSH keys (RSA 4096-bit or ed25519):

ssh-keygen -t rsa -b 4096 -C "firstname.lastname@worldline.com"

Passphrase Requirements

Your passphrase must be non-empty and meet the following criteria:

  • At least 16 characters
  • At least 1 lowercase letter
  • At least 1 uppercase letter
  • At least 1 digit
  • At least 1 special character
  • Must be different from your Okta password

Upload Your Public Key

Upload your public key to your profile to enable SSH access:

cat ~/.ssh/id_rsa.pub

Then set your identity:

ssh-add

Login

  • Linux hosts: use your login without the realm (e.g., fuser instead of fuser@ingenico.com)

    ssh fuser@mymachine0101e1.welcome.sb.eu.ginfra.net
  • Windows hosts (RDP): use BASTIONEU\fuser

PuTTY (Windows)

  1. Convert your private key to PuTTY format using puttygen
  2. Load the private key, enter the passphrase, and save as .ppk
  3. In PuTTY, go to Connection > SSH > Auth and set the private key file

On this page