Zimbra Server is the core of Zimbra Collaboration Server; it is designed with an extremely stable and modular architecture using proven open source technologies. Zimbra Server provides tremendous flexibility because it contains all of the components necessary to run your Linux or Mac based email and calendar messaging infrastructure out of the box; it also connects to just about every popular end-user client through the many standard protocols it supports.
One of Zimbra's core values is to holistically emphasize safety and security. Hence we have built in best-of-breed measures to make Zimbra Collaboration Server highly secure. This applies to both end users (virus, spam, phishing protection) and to the overall ZCS architecture / deployment framework (authentication, encryption).
The ZCS server comes embedded with ClamAV, the award-winning open source AV system. It is deployed as an extension of our Postfix MTA. Its threat definitions (anti-virus, anti-worm, anti-phishing) are updated multiple times each day to maximize protection. It is enabled during ZCS installation, so all 'end points' running against the Zimbra server have AV protection (Outlook, ZCS web client) out-of-the-box.
You are free to use ClamAV or you can choose to run any third-party alternative. We provide a plug-in framework to make adding other services easy.
End users running the ZCS web client running on a Linux-based ZCS server also have an additional layer of protection- attachments can be viewed as html rather than being downloaded. Keeping the attachment server side is more secure and also more convenient for end users (fewer clicks).
Similar to our AV solution, ZCS also comes with built in anti-spam filtering on the server using open source tools SpamAssassin and DSPAM. These tools support ongoing training (what is spam and what isn't), allowing organizations to optimize performance in their own environment. Each package is enabled during ZCS installation, receives regular updates, and spam training is automatically on to let users train spam filters as they move messages in and out of their Junk folders.
To support highly secure deployments Zimbra Collaboration Server is designed with a classic network security model where server-side systems must be trusted, but the client-side need not be. Thus, with the server physically protected businesses and organizations can deliver secure messaging and collaboration to their end users anywhere, even on their home computers, public Internet kiosks, etc. (without being forced to deploy costly Virtual Private Networks).
Key security framework methodologies:
The ZCS web client is an Ajax-based application. While it does rely on standard web platform technologies, Ajax has many inherit advantages over traditional products: