macOS processes › Security and privacy
What is trustd on Mac?
trustd checks digital certificates for macOS and apps. It decides whether a website's certificate or an app's signing certificate can be trusted, including whether it has been revoked.
What it does
Every secure connection, like a website over HTTPS or an app talking to its server, comes with a certificate. trustd verifies the chain of trust, uses its caches, and sometimes asks the issuer whether the certificate is still valid. Separate copies run for the system, for your user account and for some macOS services.
Why it gets busy
- Many new secure connections at once, like opening a browser with lots of tabs.
- A slow network or a hotel or airport Wi-Fi login page that delays revocation checks.
- Security software or a corporate proxy that inspects encrypted traffic with its own certificates.
- Rebuilding its caches after a macOS update.
Why is trustd using so much CPU?
trustd verifies certificates for secure connections and apps. Spikes come from many new connections at once, slow revocation checks, or software that intercepts encrypted traffic.
Is it safe to quit?
macOS restarts it, but secure connections and app checks stall while it's gone, so it rarely helps.
The real trustd is at /usr/libexec/trustd. A trustd running from anywhere else is suspicious.
How to calm it down
- Give it a few minutes after an update or after opening many tabs.
- If you use a VPN, proxy or security product that inspects traffic, make sure it's up to date.
- Make sure Set time and date automatically is on in System Settings › General › Date & Time. A wrong clock breaks certificate checks.
In SystemWatch
SystemWatch combines trustd's copies into one row, and History shows whether its spikes follow opening your browser or connecting to a VPN.