PowerChute connects to the vCenter Server to perform VM migration, VM shutdown, vApp shutdown, and VMware host shutdown operations.
![]() |
It is recommended that you configure an Active Directory user account with the Administrator role for vCenter Server and the VMware hosts being managed by PowerChute. If Active Directory is not available, it is recommended that you configure a local user account with the Administrator role that exists on vCenter Server and on each of the VMware hosts being managed by PowerChute. If vCenter Server is running on a VM you must configure an Active Directory account or shared Local User account for host shutdown commands to work correctly. For more information see Active Directory VMware Configuration. |
If the vCenter Server is unavailable when a critical UPS event occurs, PowerChute will still be able to connect directly to the VMware hosts using this Active Directory or shared local user account to shut down VMs and the hosts themselves.
VM migration and vApp shutdown and startup are not supported if the vCenter Server is unavailable.
If vCenter Server is running on a VM managed by vCenter Server, the option vCenter Server Running on a VM should be selected so that PowerChute can perform additional validation when trying to locate the vCenter Server VM and its parent host.
This can also occur if VMware Tools are not installed and running on the vCenter Server VM.
This results in vCenter Server VM being shut down too early in the sequence along with the other VMs.
By enabling the checkbox PowerChute will check for these kinds of problems and display a warning message on the Host Protection page or log an event in the Event Log. If vCenter Server is installed on a Physical machine, or on a VM that is not managed by the vCenter Server, this option should not be selected.
![]() |
The checkbox is only used to aid troubleshooting – it does not control whether PowerChute will perform vCenter Server VM shutdown. If unchecked and PowerChute locates vCenter Server running on a VM on an affected Host it will still shut down the vCenter Server VM. |
The Accept Untrusted SSL Certificates checkbox is unselected by default. If left unselected, only SSL certificates signed by a trusted CA will be accepted when connecting to vCenter Server and ESXi hosts. By default, these certificates are self-signed and this will cause a cause connection error. This is for increased security and to prevent man-in-the-middle (MITM) type attacks. Select this checkbox if you want to use untrusted/self-signed SSL certificates to connect to vCenter Server and ESXi hosts.
Alternatively, you can add the vCenter Server root CA certificate to the PowerChute-keystore by following the steps below. NOTE: If SSL certificates are updated on vCenter Server/hosts, they will also need to be updated in the PowerChute-keystore also.
You must change the PowerChute-keystore password before you can add trusted root certificates to the keystore:
To download and import a trusted vCenter Server root CA certificate to PowerChute:
![]() |
For standalone hosts not managed by vCenter Server, the root CA certificate can be located on the host - /etc/vmware/ssl/rui.crt. |

Copyright
© 2020 Schneider Electric
All rights reserved
http://www.apc.com
Last Updated: 17 December, 2020
990-4595H
Send
any comments on this help to:
IE-PowerChute-feedback@schneider-electric.com