A note to anyone who reads this in the future:
Connecting directly the LDAP server and deleting the field contents of oxTrustConfAttributeResolver is **NOT** a good idea. It will cause oxTrust to fail to parse the config on startup and you'll be greeted with an HTTP 503 - Service unavailable when you try to log in to the webui.
At least -- The way I attempted to remove it is not a good idea. There may be some better surgical way to do this, I'm just not aware of it. If you do end up doing it, the only way I've found to undo it is to bring back a backup or VM snapshot of a known good configuration.