OWa will use the certificate installed in IIS and issuing a cert for installation elsewhere won't make any difference.
The only way to restrict access is via IP addresses on your firewall / router, which is not in the least bit practical.
Short answer is NO, you can't restrict access from anywhere (easily).