sudo: do not store usn if no rules are found
When ldap doesn't contain any sudorule during the initial full refresh,
usn is set to 1 instead of remaining unset and we are trying to
search modifyTimestamp>=1 during smart refresh which doesn't return any result
on openldap servers.
Reviewed-by: Jakub Hrozek <email@example.com>
(cherry picked from commit 46703740e83a66909974a5ee8d47df6a6e5076e7)