ESC

Start typing to search across invoices, services, domains, tickets, and more...

Search... Ctrl+K
aaPanel / BaoTa

aaPanel Website Setup and Free SSL Certificate: Add a Site, Point DNS, Issue Let's Encrypt and Force HTTPS

5 steps 11 min read 5 views 0
On this page

Once aaPanel (BaoTa) is installed, the next step is usually to build a website and enable HTTPS. Using an Nginx stack as the example, this guide shows how to add a site in aaPanel, point your domain, upload site files, issue a free Let's Encrypt SSL certificate with one click and force HTTPS. The steps are almost identical in the Chinese BaoTa edition and work on servers running Debian/Ubuntu or CentOS/Rocky/AlmaLinux.

Before you begin, install a web server (Nginx or Apache) and PHP in the panel, plus MySQL if you need a database, and make sure ports 80 and 443 are open in the system firewall.

Step 1: Point your domain to the server IP

At your registrar or DNS provider, add an A record for the root domain and for www, pointing to the server's public IPv4 address (add AAAA records if you use IPv6). DNS changes take anywhere from a few minutes to a few hours. Check them with:

dig +short example.com A
dig +short www.example.com A
nslookup example.com

If dig is missing, install it with apt install -y dnsutils on Debian / Ubuntu or yum install -y bind-utils on CentOS / Rocky / AlmaLinux. Wait until the returned IP matches your server — otherwise SSL validation will fail.

If the domain is proxied through a CDN (for example an "orange cloud"), HTTP file validation may fail. Switch the record to DNS-only while issuing the certificate, or use DNS validation instead.

Step 2: Add a website in aaPanel

Log in to the panel, open "Website" in the left menu and click "Add site":

  • Domain: one per line, e.g. example.com and www.example.com;
  • Root directory: defaults to /www/wwwroot/example.com — usually keep it;
  • Database: create a MySQL database if your application (e.g. WordPress) needs one, and note the database name, user and password;
  • PHP version: choose what your application requires, or "Static" for a pure HTML site.

The panel generates the Nginx site configuration automatically. Visiting http://example.com should now show the panel's default "site created successfully" page. You can also check from the server:

curl -I http://example.com

Step 3: Upload your website files

Use the panel's "Files" menu to open the site root, upload your archive and extract it with a right-click, or upload over SFTP. Then fix ownership and permissions to avoid permission errors:

chown -R www:www /www/wwwroot/example.com
find /www/wwwroot/example.com -type d -exec chmod 755 {} \;
find /www/wwwroot/example.com -type f -exec chmod 644 {} \;

Remember to delete the default index.html generated by the panel, or it may keep showing instead of your site.

Step 4: Issue a free Let's Encrypt SSL certificate

In the Website list, click "Conf" (or the site name) for your site, open the "SSL" tab and choose "Let's Encrypt":

  • Choose "File verification" if the domain resolves correctly and port 80 is reachable; if you use a CDN or port 80 is unavailable, choose "DNS verification" and add the TXT record shown;
  • Tick the domains to include (root and www);
  • Click "Apply" and wait a few seconds; the certificate is deployed to the site automatically.

Let's Encrypt certificates are valid for 90 days, and the panel renews them automatically through a scheduled task. Check the certificate dates with:

echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -issuer -dates

Step 5: Force HTTPS

After the certificate is deployed, turn on "Force HTTPS" on the SSL tab so every HTTP request is 301-redirected to HTTPS. The panel adds a rule like the following to the site's Nginx server block; if you edit the config by hand you can add it yourself:

if ($server_port !~ 443){
    rewrite ^(/.*)$ https://$host$1 permanent;
}

Verify the redirect:

curl -I http://example.com

A 301 Moved Permanently with a Location header pointing to https means it works. If your application (e.g. WordPress) still stores an http site URL, update it to https to avoid mixed-content warnings.

FAQ

Let's Encrypt validation failed. What should I check?

Confirm that the domain resolves to this server, port 80 is open in the firewall, no rule or hotlink protection blocks /.well-known/, and no CDN proxy is in front. Alternatively, switch to DNS verification.

After forcing HTTPS I get "too many redirects".

This usually happens when a CDN's SSL mode is "Flexible", so it talks to your server over HTTP. Set the CDN SSL mode to "Full", or temporarily disable Force HTTPS while troubleshooting.

The certificate did not renew automatically.

Check under "Cron" that the renewal task exists and runs successfully, and whether DNS or port 80 changed before expiry. You can also renew manually from the SSL tab.

If you still need help, submit a ticket to IMIDC 24/7 technical support with your domain and the error message.

Was this answer helpful?

Related Tutorials