It was not fixed for my situation, when the main site was 6.38 and the clients were still 6.37.3.
It was “fixed” by upgrading every router to 6.38 which was not planned this day.
This still means that IPsec with xAuth and a password longer than 31 Chars is treated differently in ROS 6.37.3 than in 6.38 which leads to problems when “old” clients try to connect.