Hi Sascha,
Welcome to the forums!
There are a number of posters here in the forums running large Zimbra systems with more than 100K users.
For high-availability, Zimbra supports Red Hat Cluster. You can also use hardware duplicated (also called "fault tolerant") servers from
Stratus or
NEC, both of which are VMware certified. Our preference is to use fault-tolerant servers over RH Cluster because they require much less administration and maintenance over the long-term than a software-based cluster and, in our experience, provide higher uptimes.
VMware also have their own HA and DRS offerings, too, which I would encourage you to evaluate as well.
As regards security, there have been only a few exploit-related security patches Zimbra has released over the fours years in which we and our clients have been using Zimbra. The key open-source components within Zimbra have good security track records as well. An external Nessus scan against a Zimbra server for example won't show much in the way of problems at all.
Planning the architecture for 100K users however requires an evaluation of your mail volumes, the features you intend to use, the methods by which users will connect, and a number of other items to ensure you get the performance you need at a good price.
Hope that helps,
Mark
__________________
___________________________________
L. Mark Stone, CIO
"Uptime. All the time."
477 Congress Street | Portland, ME 04101-3431 | (207) 772-5678
proactive maintenance and monitoring | technology consulting
Zimbra groupware | EMR implementations | private cloud hosting