Dúvida Spring Security

Bom dia pessoal… estou com um problema… estou tentando implementar Spring Security em meu projeto… só que sempre está dando acesso negado. só funciona se eu colocar o usuário direto no meu arquivo xml dessa forma:

<user-service>
	<user name="daniel" password="81dc9bdb52d04dc20036dbd8313ed055" authorities="ROLE_SUPRIMENTOS" />
</user-service>

abaixo segue o meu arquivo completo

<?xml version="1.0" encoding="UTF-8"?>
<beans:beans xmlns="http://www.springframework.org/schema/security"
	xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:beans="http://www.springframework.org/schema/beans"
	xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans.xsd http://www.springframework.org/schema/security http://www.springframework.org/schema/security/spring-security-3.1.xsd">


	<beans:bean name="conexao"
		class="org.springframework.jdbc.datasource.DriverManagerDataSource">
		<beans:property name="driverClassName" value="oracle.jdbc.driver.OracleDriver" />
		<beans:property name="url" value="jdbc:oracle:thin:@//192.168.15.93:1521/ORA10G1" />
		<beans:property name="username" value="sapiens2" />
		<beans:property name="password" value="senior2" />
	</beans:bean>

	<http auto-config="true" access-denied-page="/pages/403.jsf">
		<!-- Criar os Usuarios do Sistema -->
		<intercept-url pattern="/pages/suprimentos/*" access="ROLE_SUPRIMENTOS" />
		<intercept-url pattern="/pages/compras/*" access="ROLE_COMPRAS" />

		<intercept-url pattern="/images/*" access="ROLE_SUPRIMENTOS, ROLE_COMPRAS" />
		<intercept-url pattern="/css/*" access="ROLE_SUPRIMENTOS, ROLE_COMPRAS" />
		<intercept-url pattern="/jquery/*" access="ROLE_SUPRIMENTOS, ROLE_COMPRAS" />

		<form-login login-page="/pages/login.jsf"
			authentication-failure-url="/pages/login.jsf?error=true"
			username-parameter="usuario" password-parameter="senha"
			default-target-url="/pages/suprimentos/inicio.jsf" />

		<logout logout-success-url="/pages/login.jsf" delete-cookies="true"
			invalidate-session="true" />
	</http>

	<authentication-manager>
		<authentication-provider>
			<user-service>
				<user name="daniel" password="81dc9bdb52d04dc20036dbd8313ed055" authorities="ROLE_SUPRIMENTOS" />
			</user-service>

			<password-encoder hash="md5" />
			<jdbc-user-service data-source-ref="conexao"
				users-by-username-query="SELECT nomusu AS login, usu_senint AS senha,
						'true' AS enable, usu_acesol AS perfil FROM r999usu WHERE nomusu = ?"
				authorities-by-username-query="SELECT nomusu AS login, usu_acesol AS perfil
						FROM r999usu WHERE nomusu = ?" />
		</authentication-provider>
	</authentication-manager>
</beans:beans>

porque será que está acontecendo isso…quem puder me dar uma ajuda eu agradeço…

alguem