I've been able to dig up these legit CIAs:
I feel like I saw this list somewhere, but i don't really know where

.
Also, if I may add something to the legit CIA discussion, I don't even think there is any reasonable way for Roxas to sucessfully prevent legit CIA usage and/or its installation.
Since we can safely assume that BRM (or any CIA installer) will work in RxMode, since BRM can install legit CIAs and that you can run legit CIAs from sysnand without any signature patching, it would be useless to blacklist legit cia execution.
(And you could also think about the fact that people who bought 3DS with bundled games would be alienated in RxMode if the game signatures are blacklisted).
(those 2 first points can be easily countered).
Take into account a last detail : RxTools, as of right now, is only for O3DS and 2DS. O3DS users that are able to run RxTools, are also able to install legit CIAs without any additional cost (PBT-CFW, yada, yada), so it would be pointless to prevent legit CIA installation in RxMode, as it could be installed beforehand on O3DS systems, which are the majority.
As for the procedure to do so : one would restore a 9.2 [or any 7.0+ backup] sysnand backup, downgrade to 4.5 with Gatewait, install all CIA's with PBT, setup a 9.6 emunand with RxTools, restore the 9.2 sysnand backup, and inject the ticket from the 9.6 emunand to the 9.2[or 7.0+] sysnand, thus making all the legit CIAs available on 9.2 [or 7.0+] sysnand and emunand without any help from rxMode (but this is no place for me to discus any further the procedure)
Also, for people thinking this is totally off topic, I was making a point that preventing legit CIA's installation would be pointless, since there is a free (maybe tedious, but free non the less) way around that limitation for most users of RxTools.