Thats incorrect. You do need to use SSL to connect, but as stated in the EPP documentation, you only need the root cert if you want to verify the certificate presented by the EPP server. If your happy enough to run without verifying the certificate, you can connect and login to the live system...