Start typing to search across invoices, services, domains, tickets, and more...
Once aaPanel (BaoTa) is installed, the next step is usually to build a website and enable HTTPS. Using an Nginx stack as the example, this guide shows how to add a site in aaPanel, point your domain, upload site files, issue a free Let's Encrypt SSL certificate with one click and force HTTPS. The steps are almost identical in the Chinese BaoTa edition and work on servers running Debian/Ubuntu or CentOS/Rocky/AlmaLinux.
At your registrar or DNS provider, add an A record for the root domain and for www, pointing to the server's public IPv4 address (add AAAA records if you use IPv6). DNS changes take anywhere from a few minutes to a few hours. Check them with:
dig +short example.com A
dig +short www.example.com A
nslookup example.com
If dig is missing, install it with apt install -y dnsutils on Debian / Ubuntu or yum install -y bind-utils on CentOS / Rocky / AlmaLinux. Wait until the returned IP matches your server — otherwise SSL validation will fail.
Log in to the panel, open "Website" in the left menu and click "Add site":
example.com and www.example.com;/www/wwwroot/example.com — usually keep it;The panel generates the Nginx site configuration automatically. Visiting http://example.com should now show the panel's default "site created successfully" page. You can also check from the server:
curl -I http://example.com
Use the panel's "Files" menu to open the site root, upload your archive and extract it with a right-click, or upload over SFTP. Then fix ownership and permissions to avoid permission errors:
chown -R www:www /www/wwwroot/example.com
find /www/wwwroot/example.com -type d -exec chmod 755 {} \;
find /www/wwwroot/example.com -type f -exec chmod 644 {} \;
Remember to delete the default index.html generated by the panel, or it may keep showing instead of your site.
In the Website list, click "Conf" (or the site name) for your site, open the "SSL" tab and choose "Let's Encrypt":
Let's Encrypt certificates are valid for 90 days, and the panel renews them automatically through a scheduled task. Check the certificate dates with:
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -issuer -dates
After the certificate is deployed, turn on "Force HTTPS" on the SSL tab so every HTTP request is 301-redirected to HTTPS. The panel adds a rule like the following to the site's Nginx server block; if you edit the config by hand you can add it yourself:
if ($server_port !~ 443){
rewrite ^(/.*)$ https://$host$1 permanent;
}
Verify the redirect:
curl -I http://example.com
A 301 Moved Permanently with a Location header pointing to https means it works. If your application (e.g. WordPress) still stores an http site URL, update it to https to avoid mixed-content warnings.
Confirm that the domain resolves to this server, port 80 is open in the firewall, no rule or hotlink protection blocks /.well-known/, and no CDN proxy is in front. Alternatively, switch to DNS verification.
This usually happens when a CDN's SSL mode is "Flexible", so it talks to your server over HTTP. Set the CDN SSL mode to "Full", or temporarily disable Force HTTPS while troubleshooting.
Check under "Cron" that the renewal task exists and runs successfully, and whether DNS or port 80 changed before expiry. You can also renew manually from the SSL tab.
If you still need help, submit a ticket to IMIDC 24/7 technical support with your domain and the error message.